This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Microsoft First view 2018-10-10
Product Windows 10 Last view 2020-10-16
Version 1809 Type Os
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:o:microsoft:windows_10

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
7.8 2020-10-16 CVE-2020-17022

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'.

7.8 2020-10-16 CVE-2020-16976

An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16912, CVE-2020-16936, CVE-2020-16972, CVE-2020-16973, CVE-2020-16974, CVE-2020-16975.

7.8 2020-10-16 CVE-2020-16975

An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16912, CVE-2020-16936, CVE-2020-16972, CVE-2020-16973, CVE-2020-16974, CVE-2020-16976.

7.8 2020-10-16 CVE-2020-16974

An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16912, CVE-2020-16936, CVE-2020-16972, CVE-2020-16973, CVE-2020-16975, CVE-2020-16976.

7.8 2020-10-16 CVE-2020-16973

An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16912, CVE-2020-16936, CVE-2020-16972, CVE-2020-16974, CVE-2020-16975, CVE-2020-16976.

7.8 2020-10-16 CVE-2020-16972

An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16912, CVE-2020-16936, CVE-2020-16973, CVE-2020-16974, CVE-2020-16975, CVE-2020-16976.

7.8 2020-10-16 CVE-2020-16968

A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory, aka 'Windows Camera Codec Pack Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16967.

7.8 2020-10-16 CVE-2020-16967

A remote code execution vulnerability exists when the Windows Camera Codec Pack improperly handles objects in memory, aka 'Windows Camera Codec Pack Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16968.

7.5 2020-10-16 CVE-2020-16949

A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory, aka 'Microsoft Outlook Denial of Service Vulnerability'.

5.5 2020-10-16 CVE-2020-16940

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User Profile Service Elevation of Privilege Vulnerability'.

7.8 2020-10-16 CVE-2020-16939

An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.

7.8 2020-10-16 CVE-2020-16936

An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16912, CVE-2020-16972, CVE-2020-16973, CVE-2020-16974, CVE-2020-16975, CVE-2020-16976.

7.8 2020-10-16 CVE-2020-16935

An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16916.

8.8 2020-10-16 CVE-2020-16933

A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files, aka 'Microsoft Word Security Feature Bypass Vulnerability'.

7.5 2020-10-16 CVE-2020-16927

A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.

7.8 2020-10-16 CVE-2020-16924

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.

7.8 2020-10-16 CVE-2020-16923

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1167.

5.5 2020-10-16 CVE-2020-16922

A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows Spoofing Vulnerability'.

5.5 2020-10-16 CVE-2020-16921

An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory, aka 'Windows Text Services Framework Information Disclosure Vulnerability'.

7.8 2020-10-16 CVE-2020-16920

An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations, aka 'Windows Application Compatibility Client Library Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16876.

5.5 2020-10-16 CVE-2020-16919

An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations, aka 'Windows Enterprise App Management Service Information Disclosure Vulnerability'.

8.8 2020-10-16 CVE-2020-16915

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.

5.5 2020-10-16 CVE-2020-16914

An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerability'.

7.8 2020-10-16 CVE-2020-16913

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16907.

7.8 2020-10-16 CVE-2020-16912

An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16936, CVE-2020-16972, CVE-2020-16973, CVE-2020-16974, CVE-2020-16975, CVE-2020-16976.

CWE : Common Weakness Enumeration

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
%idName
50% (407) CWE-269 Improper Privilege Management
15% (125) CWE-200 Information Exposure
11% (96) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
3% (27) CWE-20 Improper Input Validation
3% (26) CWE-787 Out-of-bounds Write
2% (23) CWE-59 Improper Link Resolution Before File Access ('Link Following')
1% (12) CWE-404 Improper Resource Shutdown or Release
1% (11) CWE-611 Information Leak Through XML External Entity File Disclosure
1% (10) CWE-125 Out-of-bounds Read
0% (8) CWE-665 Improper Initialization
0% (5) CWE-732 Incorrect Permission Assignment for Critical Resource
0% (5) CWE-190 Integer Overflow or Wraparound
0% (4) CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
0% (3) CWE-522 Insufficiently Protected Credentials
0% (3) CWE-416 Use After Free
0% (3) CWE-362 Race Condition
0% (3) CWE-347 Improper Verification of Cryptographic Signature
0% (3) CWE-295 Certificate Issues
0% (3) CWE-264 Permissions, Privileges, and Access Controls
0% (3) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
0% (3) CWE-19 Data Handling
0% (2) CWE-755 Improper Handling of Exceptional Conditions
0% (2) CWE-434 Unrestricted Upload of File with Dangerous Type
0% (2) CWE-354 Improper Validation of Integrity Check Value
0% (2) CWE-327 Use of a Broken or Risky Cryptographic Algorithm

Snort® IPS/IDS

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
Date Description
2020-10-08 Microsoft Windows kernel driver escalation of privilege attempt
RuleID : 55188 - Type : OS-WINDOWS - Revision : 1
2020-10-08 Microsoft Windows kernel driver escalation of privilege attempt
RuleID : 55187 - Type : OS-WINDOWS - Revision : 1
2020-10-06 Microsoft Windows kernel DirectComposition use after free attempt
RuleID : 55162 - Type : OS-WINDOWS - Revision : 1
2020-10-06 Microsoft Windows kernel DirectComposition use after free attempt
RuleID : 55161 - Type : OS-WINDOWS - Revision : 1
2020-10-06 Microsoft Windows DirectX kernel driver local privilege escalation attempt
RuleID : 55146 - Type : OS-WINDOWS - Revision : 1
2020-10-06 Microsoft Windows DirectX kernel driver local privilege escalation attempt
RuleID : 55145 - Type : OS-WINDOWS - Revision : 1
2020-10-06 Microsoft Windows win32k kernel driver use after free attempt
RuleID : 55144 - Type : OS-WINDOWS - Revision : 1
2020-10-06 Microsoft Windows win32k kernel driver use after free attempt
RuleID : 55143 - Type : OS-WINDOWS - Revision : 1
2020-10-06 Microsoft Windows CLFS Driver elevation of privilege attempt
RuleID : 55142 - Type : FILE-OTHER - Revision : 1
2020-10-06 Microsoft Windows CLFS Driver elevation of privilege attempt
RuleID : 55141 - Type : FILE-OTHER - Revision : 1
2020-09-19 Windows print spooler elevation of privilege attempt
RuleID : 54820 - Type : OS-WINDOWS - Revision : 1
2020-09-19 Windows print spooler elevation of privilege attempt
RuleID : 54819 - Type : OS-WINDOWS - Revision : 1
2020-09-19 Windows Print Spooler elevation of privilege attempt
RuleID : 54818 - Type : OS-WINDOWS - Revision : 1
2020-09-19 Windows Print Spooler elevation of privilege attempt
RuleID : 54817 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows TCPIP kernel driver use-after-free attempt
RuleID : 54766 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows TCPIP kernel driver use-after-free attempt
RuleID : 54765 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows kernel information disclosure attempt
RuleID : 54754 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows kernel information disclosure attempt
RuleID : 54753 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows GDI elevation of privilege attempt
RuleID : 54746 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows GDI elevation of privilege attempt
RuleID : 54745 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows GDI privilege escalation attempt
RuleID : 54738 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows GDI privilege escalation attempt
RuleID : 54737 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows DNS Resolver local privilege escalation attempt
RuleID : 54736 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows DNS Resolver local privilege escalation attempt
RuleID : 54735 - Type : OS-WINDOWS - Revision : 1
2020-09-15 Microsoft Windows AFD kernel driver privilege escalation attempt
RuleID : 54734 - Type : OS-WINDOWS - Revision : 1

Nessus® Vulnerability Scanner

id Description
2018-10-22 Name: An application installed on the remote macOS or Mac OS X host is affected by ...
File: macos_ms18_oct_office.nasl - Type: ACT_GATHER_INFO