Summary
Detail | |||
---|---|---|---|
Vendor | Microsoft | First view | 2015-09-08 |
Product | Windows 10 | Last view | 2021-01-12 |
Version | - | Type | Os |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | x64 | ||
Other | * | ||
CPE Product | cpe:2.3:o:microsoft:windows_10 |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
7.8 | 2021-01-12 | CVE-2021-1710 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability |
7.8 | 2021-01-12 | CVE-2021-1704 | Windows Hyper-V Elevation of Privilege Vulnerability |
7.7 | 2021-01-12 | CVE-2021-1692 | Hyper-V Denial of Service Vulnerability This CVE ID is unique from CVE-2021-1691. |
8.8 | 2020-10-16 | CVE-2020-16891 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. |
5.5 | 2020-09-11 | CVE-2020-16854 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0928, CVE-2020-1033, CVE-2020-1589, CVE-2020-1592. |
7.8 | 2020-09-11 | CVE-2020-1598 | An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. |
5.3 | 2020-09-11 | CVE-2020-1596 | A information disclosure vulnerability exists when TLS components use weak hash algorithms, aka 'TLS Information Disclosure Vulnerability'. |
8.8 | 2020-09-11 | CVE-2020-1593 | A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects, aka 'Windows Media Audio Decoder Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1508. |
5.5 | 2020-09-11 | CVE-2020-1589 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0928, CVE-2020-1033, CVE-2020-1592, CVE-2020-16854. |
7.8 | 2020-09-11 | CVE-2020-1559 | An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka 'Windows Storage Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0886. |
7.8 | 2020-09-11 | CVE-2020-0998 | An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. |
7.8 | 2020-09-11 | CVE-2020-0997 | A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory, aka 'Windows Camera Codec Pack Remote Code Execution Vulnerability'. |
5.5 | 2020-09-11 | CVE-2020-0941 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1250. |
8.8 | 2020-09-11 | CVE-2020-0922 | A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory, aka 'Microsoft COM for Windows Remote Code Execution Vulnerability'. |
5.5 | 2020-09-11 | CVE-2020-0921 | An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1083. |
5.5 | 2020-09-11 | CVE-2020-0914 | An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Information Disclosure Vulnerability'. |
7.8 | 2020-09-11 | CVE-2020-0912 | An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Function Discovery SSDP Provider Elevation of Privilege Vulnerability'. |
7.8 | 2020-09-11 | CVE-2020-0911 | An elevation of privilege vulnerability exists when Windows Modules Installer improperly handles objects in memory, aka 'Windows Modules Installer Elevation of Privilege Vulnerability'. |
7.8 | 2020-09-11 | CVE-2020-0886 | An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka 'Windows Storage Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1559. |
5.5 | 2020-09-11 | CVE-2020-0875 | An information disclosure vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Information Disclosure Vulnerability'. |
7.8 | 2020-09-11 | CVE-2020-0839 | An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory, aka 'Windows dnsrslvr.dll Elevation of Privilege Vulnerability'. |
7.8 | 2020-09-11 | CVE-2020-0838 | An elevation of privilege vulnerability exists when NTFS improperly checks access, aka 'NTFS Elevation of Privilege Vulnerability'. |
7.8 | 2020-09-11 | CVE-2020-0790 | A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'. |
7.8 | 2020-09-11 | CVE-2020-0782 | An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services improperly handle objects in memory, aka 'Windows Cryptographic Catalog Services Elevation of Privilege Vulnerability'. |
6.5 | 2020-08-17 | CVE-2020-1577 | An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
27% (26) | CWE-20 | Improper Input Validation |
24% (23) | CWE-269 | Improper Privilege Management |
23% (22) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
10% (10) | CWE-200 | Information Exposure |
3% (3) | CWE-264 | Permissions, Privileges, and Access Controls |
2% (2) | CWE-732 | Incorrect Permission Assignment for Critical Resource |
1% (1) | CWE-787 | Out-of-bounds Write |
1% (1) | CWE-522 | Insufficiently Protected Credentials |
1% (1) | CWE-434 | Unrestricted Upload of File with Dangerous Type |
1% (1) | CWE-346 | Origin Validation Error |
1% (1) | CWE-331 | Insufficient Entropy |
1% (1) | CWE-327 | Use of a Broken or Risky Cryptographic Algorithm |
1% (1) | CWE-295 | Certificate Issues |
1% (1) | CWE-284 | Access Control (Authorization) Issues |
1% (1) | CWE-254 | Security Features |
Information Assurance Vulnerability Management (IAVM)
id | Description |
---|---|
2015-B-0111 | Microsoft Hyper-V Security Bypass Vulnerability (MS15-105) Severity: Category II - VMSKEY: V0061371 |
2015-A-0212 | Multiple Vulnerabilities in Microsoft Graphics Component (MS15-097) Severity: Category II - VMSKEY: V0061385 |
Snort® IPS/IDS
Date | Description |
---|---|
2020-10-08 | Microsoft Windows kernel driver escalation of privilege attempt RuleID : 55188 - Type : OS-WINDOWS - Revision : 1 |
2020-10-08 | Microsoft Windows kernel driver escalation of privilege attempt RuleID : 55187 - Type : OS-WINDOWS - Revision : 1 |
2020-09-15 | Microsoft Windows TCPIP kernel driver use-after-free attempt RuleID : 54766 - Type : OS-WINDOWS - Revision : 1 |
2020-09-15 | Microsoft Windows TCPIP kernel driver use-after-free attempt RuleID : 54765 - Type : OS-WINDOWS - Revision : 1 |
2020-09-15 | Microsoft Windows GDI privilege escalation attempt RuleID : 54738 - Type : OS-WINDOWS - Revision : 1 |
2020-09-15 | Microsoft Windows GDI privilege escalation attempt RuleID : 54737 - Type : OS-WINDOWS - Revision : 1 |
2020-08-13 | Microsoft Windows Address Book Contact file integer overflow attempt RuleID : 54533 - Type : FILE-OTHER - Revision : 1 |
2020-08-13 | Microsoft Windows Address Book Contact file integer overflow attempt RuleID : 54532 - Type : FILE-OTHER - Revision : 1 |
2020-08-13 | Microsoft Windows Address Book Contact file integer overflow attempt RuleID : 54531 - Type : FILE-OTHER - Revision : 1 |
2020-08-13 | Microsoft Windows Address Book Contact file integer overflow attempt RuleID : 54530 - Type : FILE-OTHER - Revision : 1 |
2020-08-13 | Microsoft Windows Address Book Contact file integer overflow attempt RuleID : 54529 - Type : FILE-OTHER - Revision : 1 |
2020-08-13 | Microsoft Windows Address Book Contact file integer overflow attempt RuleID : 54528 - Type : FILE-OTHER - Revision : 1 |
2020-06-11 | Microsoft Windows Win32k privilege escalation attempt RuleID : 53933 - Type : OS-WINDOWS - Revision : 1 |
2020-06-11 | Microsoft Windows Win32k privilege escalation attempt RuleID : 53932 - Type : OS-WINDOWS - Revision : 1 |
2016-03-14 | Microsoft Windows gpuenergydrv.sys driver privilege escalation attempt RuleID : 36990 - Type : OS-WINDOWS - Revision : 2 |
2016-03-14 | Microsoft Windows gpuenergydrv.sys driver privilege escalation attempt RuleID : 36989 - Type : OS-WINDOWS - Revision : 2 |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2016-09-13 | Name: The remote host is affected by an information disclosure vulnerability. File: smb_nt_ms16-113.nasl - Type: ACT_GATHER_INFO |
2016-08-09 | Name: The remote host is affected by an information disclosure vulnerability. File: smb_nt_ms16-103.nasl - Type: ACT_GATHER_INFO |
2016-01-13 | Name: The remote Windows host is affected by multiple vulnerabilities. File: smb_nt_ms16-005.nasl - Type: ACT_GATHER_INFO |
2016-01-13 | Name: The remote Windows host is affected by multiple vulnerabilities. File: smb_nt_ms16-007.nasl - Type: ACT_GATHER_INFO |
2015-12-08 | Name: The remote Windows host is affected by multiple elevation of privilege vulner... File: smb_nt_ms15-135.nasl - Type: ACT_GATHER_INFO |
2015-09-09 | Name: The remote host is affected by multiple vulnerabilities. File: smb_nt_ms15-097.nasl - Type: ACT_GATHER_INFO |
2015-09-08 | Name: The remote Windows host is affected by a security bypass vulnerability. File: smb_nt_ms15-105.nasl - Type: ACT_GATHER_INFO |