📦 Windows 10 20h2

by Microsoft

🔍 What is Windows 10 20h2?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-35744

CRITICAL CVSS 9.8 May 31, 2023

CVE-2022-35744 is a critical remote code execution vulnerability in Windows Point-to-Point Protocol (PPP) that allows unauthenticated attackers to execute arbitrary code on affected systems. This affe...

CVE-2023-24943

CRITICAL CVSS 9.8 May 9, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General Multicast) protocol packets. It affects Windows sys...

CVE-2023-28250

CRITICAL CVSS 9.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted PGM (Pragmatic General Multicast) packets. It affects Windows systems with...

CVE-2023-21554

CRITICAL CVSS 9.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft Message Queuing (MSMQ) by sending specially crafted packets. It affects Windows servers and workstatio...

CVE-2023-23415

CRITICAL CVSS 9.8 Mar 14, 2023

This critical vulnerability allows remote attackers to execute arbitrary code on affected systems by sending specially crafted ICMP packets. It affects Windows systems with specific network configurat...

CVE-2023-21708

CRITICAL CVSS 9.8 Mar 14, 2023

This is a critical Remote Procedure Call Runtime vulnerability that allows unauthenticated attackers to execute arbitrary code remotely on affected Windows systems. It affects Windows servers and work...

CVE-2023-21689

CRITICAL CVSS 9.8 Feb 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running Microsoft's Protected Extensible Authentication Protocol (PEAP) without authentication. It affects Windows syste...

CVE-2023-21692

CRITICAL CVSS 9.8 Feb 14, 2023

This critical vulnerability in Microsoft's Protected Extensible Authentication Protocol (PEAP) allows remote attackers to execute arbitrary code on affected systems without authentication. It affects ...

CVE-2021-31166

CRITICAL CVSS 9.8 May 11, 2021

CVE-2021-31166 is a critical remote code execution vulnerability in the Microsoft HTTP Protocol Stack (http.sys) that allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges ...

CVE-2022-35755

HIGH CVSS 7.3 May 31, 2023

This vulnerability allows attackers to gain SYSTEM-level privileges on Windows systems by exploiting the Print Spooler service. It affects Windows servers and workstations where the Print Spooler serv...

CVE-2022-35757

HIGH CVSS 7.3 May 31, 2023

This vulnerability in the Windows Cloud Files Mini Filter Driver allows attackers to gain SYSTEM-level privileges on affected Windows systems. It affects Windows 10, 11, and Server versions where the ...

CVE-2022-35743

HIGH CVSS 7.8 May 31, 2023

This vulnerability allows remote code execution through the Microsoft Windows Support Diagnostic Tool (MSDT) when processing specially crafted files. Attackers can exploit this by tricking users into ...

CVE-2022-35746

HIGH CVSS 7.8 May 31, 2023

CVE-2022-35746 is an elevation of privilege vulnerability in Windows Digital Media Receiver that allows authenticated attackers to execute arbitrary code with SYSTEM privileges. This affects Windows s...

CVE-2022-35750

HIGH CVSS 7.8 May 31, 2023

CVE-2022-35750 is a Win32k elevation of privilege vulnerability in Windows that allows an authenticated attacker to gain SYSTEM-level privileges on a compromised system. This affects Windows operating...

CVE-2022-35752

HIGH CVSS 8.1 May 31, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a flaw in the Secure Socket Tunneling Protocol (SSTP) service. Attackers could gain SYSTEM-level p...

CVE-2023-24948

HIGH CVSS 7.4 May 9, 2023

This vulnerability allows an attacker with local access to exploit a heap-based buffer overflow in Windows Bluetooth drivers to execute arbitrary code with SYSTEM privileges. It affects Windows system...

CVE-2023-28283

HIGH CVSS 8.1 May 9, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running LDAP services by sending specially crafted requests. It affects Windows servers with LDAP enabled, parti...

CVE-2023-29325

HIGH CVSS 8.1 May 9, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by exploiting a use-after-free flaw in OLE (Object Linking and Embedding) technology. Attackers can cra...

CVE-2023-29335

HIGH CVSS 7.5 May 9, 2023

CVE-2023-29335 is a security feature bypass vulnerability in Microsoft Word that allows attackers to circumvent security protections and potentially execute malicious code. This affects users of Micro...

CVE-2023-24901

HIGH CVSS 7.5 May 9, 2023

This vulnerability in Windows NFS Portmapper allows attackers to disclose sensitive information from memory. It affects Windows systems running NFS services, potentially exposing internal network deta...

CVE-2023-24903

HIGH CVSS 8.1 May 9, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running vulnerable versions of the Secure Socket Tunneling Protocol (SSTP) service. Attackers can exploit this w...

CVE-2023-24905

HIGH CVSS 7.8 May 9, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable Remote Desktop Client software. Attackers can exploit this by tricking users into connecting to a mal...

CVE-2023-24939

HIGH CVSS 7.5 May 9, 2023

CVE-2023-24939 is a denial-of-service vulnerability in Microsoft's Server for NFS (Network File System) that allows attackers to crash the service by sending specially crafted requests. This affects W...

CVE-2023-24946

HIGH CVSS 7.8 May 9, 2023

This vulnerability in Windows Backup Service allows authenticated attackers to gain SYSTEM-level privileges on affected systems. It affects Windows servers and workstations where the backup service is...

CVE-2023-21712

HIGH CVSS 8.1 Apr 27, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a flaw in the Point-to-Point Tunneling Protocol (PPTP) implementation. Attackers could gain SYSTEM...

CVE-2023-28293

HIGH CVSS 7.8 Apr 11, 2023

This Windows kernel vulnerability allows local attackers to escalate privileges from a lower-privileged account to SYSTEM-level access. It affects Windows 10, 11, and Server versions. Attackers need i...

CVE-2023-28297

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability in Windows Remote Procedure Call Service allows an authenticated attacker to execute code with SYSTEM privileges by exploiting a use-after-free condition. It affects Windows systems...

CVE-2023-28302

HIGH CVSS 7.5 Apr 11, 2023

This vulnerability in Microsoft Message Queuing (MSMQ) allows attackers to cause a denial of service by sending specially crafted packets to the service. Systems running MSMQ with the service enabled ...

CVE-2023-28272

HIGH CVSS 7.8 Apr 11, 2023

CVE-2023-28272 is a Windows kernel elevation of privilege vulnerability that allows authenticated attackers to execute arbitrary code with SYSTEM privileges. This affects Windows operating systems whe...

CVE-2023-28274

HIGH CVSS 7.8 Apr 11, 2023

This vulnerability allows an attacker to gain SYSTEM-level privileges on Windows systems by exploiting a flaw in the Win32k driver. It affects Windows operating systems where an attacker already has l...

CVE-2023-28238

HIGH CVSS 7.5 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected Windows systems by sending specially crafted packets to the Internet Key Exchange (IKE) protocol service. It affects Wi...

CVE-2023-28241

HIGH CVSS 7.5 Apr 11, 2023

This vulnerability in Windows Secure Socket Tunneling Protocol (SSTP) allows attackers to cause a denial of service by sending specially crafted packets. It affects Windows systems with SSTP enabled, ...

CVE-2023-28227

HIGH CVSS 7.5 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems via specially crafted Bluetooth packets. Attackers can exploit this without authentication when Bluetooth is ena...

CVE-2023-28229

HIGH CVSS 7.0 Apr 11, 2023

This vulnerability in Windows CNG Key Isolation Service allows attackers to elevate privileges from a low-privileged user account to SYSTEM level. It affects Windows systems where the CNG service is r...

CVE-2023-28232

HIGH CVSS 7.5 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a flaw in the Point-to-Point Tunneling Protocol (PPTP) implementation. Attackers could gain SYSTEM...

CVE-2023-28236

HIGH CVSS 7.8 Apr 11, 2023

This vulnerability allows an authenticated attacker to execute arbitrary code with kernel privileges on Windows systems. It enables local privilege escalation from a lower-privileged account to SYSTEM...

CVE-2023-28216

HIGH CVSS 7.0 Apr 11, 2023

This vulnerability allows an authenticated attacker to exploit a flaw in Windows Advanced Local Procedure Call (ALPC) to elevate privileges on a local system. It affects Windows operating systems and ...

CVE-2023-28218

HIGH CVSS 7.0 Apr 11, 2023

This vulnerability in the Windows Ancillary Function Driver for WinSock allows attackers to escalate privileges from a low-privileged user account to SYSTEM level. It affects Windows operating systems...

CVE-2023-28220

HIGH CVSS 8.1 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable Layer 2 Tunneling Protocol (L2TP) implementations. Attackers can exploit this without authentication ...

CVE-2023-28222

HIGH CVSS 7.1 Apr 11, 2023

This Windows kernel vulnerability allows attackers to elevate privileges from user mode to kernel mode, potentially gaining SYSTEM-level access. It affects Windows operating systems and requires an at...

CVE-2023-28224

HIGH CVSS 7.1 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a flaw in the Point-to-Point Protocol over Ethernet (PPPoE) component. Attackers could gain SYSTEM...

CVE-2023-24925

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft PostScript and PCL6 Class Printer Drivers. Attackers can exploit this by sending specially crafted print...

CVE-2023-24927

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems using Microsoft PostScript and PCL6 Class Printer Drivers. Attackers can exploit this by sending specially crafted print...

CVE-2023-24929

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems using vulnerable Microsoft PostScript and PCL6 Class Printer Drivers. Attackers can exploit this by sending specially cr...

CVE-2023-24884

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems using vulnerable Microsoft PostScript and PCL6 printer drivers. Attackers can exploit this by sending specially crafted ...

CVE-2023-24886

HIGH CVSS 8.8 Apr 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems using vulnerable Microsoft PostScript and PCL6 Class Printer Drivers. Attackers can exploit this by sending specially cr...

CVE-2023-21769

HIGH CVSS 7.5 Apr 11, 2023

This vulnerability in Microsoft Message Queuing (MSMQ) allows an unauthenticated attacker to send specially crafted packets to an MSMQ server, causing it to crash and resulting in a denial of service....

CVE-2023-24907

HIGH CVSS 8.8 Mar 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on systems using vulnerable Microsoft PostScript and PCL6 printer drivers. Attackers can exploit this by sending specially crafted ...

CVE-2023-24909

HIGH CVSS 8.8 Mar 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting integer overflow in Microsoft PostScript and PCL6 Class Printer Drivers. It affects Windows syste...