Vulnerabilities
Vulnerable Software
Microsoft:  >> Windows 10 1803  Security Vulnerabilities
CVE-2020-0968
Known exploited
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.
CVSS Score
7.5
EPSS Score
0.334
Published
2020-04-15
CVE-2020-0938
Known exploited
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.
CVSS Score
7.8
EPSS Score
0.881
Published
2020-04-15
CVE-2020-0787
Known exploited
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
CVSS Score
7.8
EPSS Score
0.656
Published
2020-03-12
CVE-2020-0683
Known exploited
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
CVSS Score
7.8
EPSS Score
0.294
Published
2020-02-11
CVE-2020-0674
Known exploited
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
CVSS Score
7.5
EPSS Score
0.936
Published
2020-02-11
CVE-2020-0646
Known exploited
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
CVSS Score
9.8
EPSS Score
0.931
Published
2020-01-14
CVE-2020-0638
Known exploited
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.
CVSS Score
7.8
EPSS Score
0.01
Published
2020-01-14
CVE-2020-0601
Known exploited
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
CVSS Score
8.1
EPSS Score
0.941
Published
2020-01-14
CVE-2019-1429
Known exploited
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
CVSS Score
7.5
EPSS Score
0.653
Published
2019-11-12
CVE-2019-1405
Known exploited
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
CVSS Score
7.8
EPSS Score
0.477
Published
2019-11-12


Contact Us

Shodan ® - All rights reserved