Windows 10 1909
Vendor:
First CVE: Dec 11, 2013 · Active for 12 years
61
Total CVEs
More Total CVEs than 98% of tracked products
10.2
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
86.9%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Windows 10 1909 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2013
12 years ago
Most Recent CVE
Aug 7, 2024
718 days ago
CVE Severity & Scoring
Windows 10 190961 CVEs
90%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local43 (70.5%)
Network18 (29.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (88.5%)
High7 (11.5%)
Unknown0 (0.0%)
User Interaction
None41 (67.2%)
Unknown0 (0.0%)
Required20 (32.8%)
Privileges Required
Low39 (63.9%)
High0 (0.0%)
None22 (36.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (61 CVEs).
61 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-0796CRITICAL A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Re | Mar 12, 2020 | 10.0 | 99 | YES | YES |
CVE-2020-0646CRITICAL A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. | Jan 14, 2020 | 9.8 | 99 | YES | YES |
CVE-2021-40444HIGH <p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to expl | Sep 15, 2021 | 8.8 | 97 | YES | YES |
CVE-2020-0601HIGH A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by u | Jan 14, 2020 | 8.1 | 97 | YES | YES |
CVE-2022-26923HIGH Active Directory Domain Services Elevation of Privilege Vulnerability | May 10, 2022 | 8.8 | 96 | YES | YES |
CVE-2021-1675HIGH Windows Print Spooler Remote Code Execution Vulnerability | Jun 8, 2021 | 7.8 | 96 | YES | YES |
CVE-2021-1732HIGH Windows Win32k Elevation of Privilege Vulnerability | Feb 25, 2021 | 7.8 | 95 | YES | YES |
CVE-2020-0674HIGH A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerabil | Feb 11, 2020 | 7.5 | 95 | YES | YES |
CVE-2021-40449HIGH Win32k Elevation of Privilege Vulnerability | Oct 13, 2021 | 7.8 | 94 | YES | YES |
CVE-2021-36934HIGH <p>An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) d | Jul 22, 2021 | 7.8 | 94 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (61 CVEs).
CISA KEV
53 CVEs
86.9% of CVEs· 99th percentile
Metasploit
13 CVEs
21.3% of CVEs· 97th percentile
Nuclei
2 CVEs
3.3% of CVEs· 97th percentile
ExploitDB
5 CVEs
8.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (61 CVEs).
Media Mentions
Signals from CVEs in this product scope (61 CVEs).
Top CNAs Publishing CVEs For Windows 10 1909
Top CWEs
Versions
No cataloged versions.