Vulnerabilities > Microsoft > Windows 10 > 1803

DATE CVE VULNERABILITY TITLE RISK
2020-09-11 CVE-2020-0922 Unspecified vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory.
network
low complexity
microsoft
8.8
2020-09-11 CVE-2020-0921 Unspecified vulnerability in Microsoft products
Microsoft Graphics Component Denial of Service Vulnerability
local
low complexity
microsoft
5.5
2020-09-11 CVE-2020-0914 Unspecified vulnerability in Microsoft products
<p>An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory.
local
low complexity
microsoft
5.5
2020-09-11 CVE-2020-0912 Unspecified vulnerability in Microsoft products
<p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system.
local
high complexity
microsoft
7.0
2020-09-11 CVE-2020-0911 Unspecified vulnerability in Microsoft products
<p>An elevation of privilege vulnerability exists when Windows Modules Installer improperly handles objects in memory.
local
low complexity
microsoft
7.8
2020-09-11 CVE-2020-0908 Unspecified vulnerability in Microsoft products
<p>A remote code execution vulnerability exists when the Windows Text Service Module improperly handles memory.
network
high complexity
microsoft
7.5
2020-09-11 CVE-2020-0904 Improper Input Validation vulnerability in Microsoft products
<p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.</p> <p>The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests.</p>
local
low complexity
microsoft CWE-20
6.5
2020-09-11 CVE-2020-0890 Unspecified vulnerability in Microsoft products
<p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.</p> <p>The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests.</p>
local
low complexity
microsoft
6.5
2020-09-11 CVE-2020-0886 Unspecified vulnerability in Microsoft products
<p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations.
local
low complexity
microsoft
7.8
2020-09-11 CVE-2020-0875 Unspecified vulnerability in Microsoft products
<p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls.
local
low complexity
microsoft
5.5