Vulnerabilities > Microsoft > Windows 10 > 1803

DATE CVE VULNERABILITY TITLE RISK
2020-05-21 CVE-2020-1134 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-05-21 CVE-2020-1132 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-05-21 CVE-2020-1131 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-05-21 CVE-2020-1126 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft products
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
network
microsoft CWE-119
critical
9.3
2020-05-21 CVE-2020-1125 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'.
network
microsoft CWE-269
6.8
2020-05-21 CVE-2020-1124 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-05-21 CVE-2020-1123 Incorrect Permission Assignment for Critical Resource vulnerability in Microsoft products
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'.
local
low complexity
microsoft CWE-732
2.1
2020-05-21 CVE-2020-1118 Unspecified vulnerability in Microsoft Windows 10 and Windows Server 2019
A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges, aka 'Microsoft Windows Transport Layer Security Denial of Service Vulnerability'.
network
low complexity
microsoft
7.8
2020-05-21 CVE-2020-1117 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft products
A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory, aka 'Microsoft Color Management Remote Code Execution Vulnerability'.
network
microsoft CWE-119
critical
9.3
2020-05-21 CVE-2020-1116 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
2.1