Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows 10 Version 1909.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-30138HIGH | Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29104, CVE-2022-29132. May 18, 2022 | CVSS7.8v3.1 | EPSS0.995% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29142HIGH | Windows Kernel Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29133. May 10, 2022 | CVSS7.0v3.1 | EPSS5.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29141HIGH | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29130, CVE-2022-29131, CVE-2022-29137, CVE-2022-29139. May 10, 2022 | CVSS8.8v3.1 | EPSS2.67% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29140MEDIUM | Windows Print Spooler Information Disclosure VulnerabilityWindows Print Spooler Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-29114. May 10, 2022 | CVSS5.5v3.1 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29139HIGH | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29130, CVE-2022-29131, CVE-2022-29137, CVE-2022-29141. May 10, 2022 | CVSS8.8v3.1 | EPSS2.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29137HIGH | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29130, CVE-2022-29131, CVE-2022-29139, CVE-2022-29141. May 10, 2022 | CVSS8.8v3.1 | EPSS2.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29132HIGH | Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29104. May 10, 2022 | CVSS7.8v3.1 | EPSS0.666% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29131HIGH | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29130, CVE-2022-29137, CVE-2022-29139, CVE-2022-29141. May 10, 2022 | CVSS8.8v3.1 | EPSS2.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29130CRITICAL | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29131, CVE-2022-29137, CVE-2022-29139, CVE-2022-29141. May 10, 2022 | CVSS9.8v3.1 | EPSS3.81% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29129HIGH | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29130, CVE-2022-29131, CVE-2022-29137, CVE-2022-29139, CVE-2022-29141. May 10, 2022 | CVSS8.8v3.1 | EPSS2.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29128HIGH | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityWindows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29129, CVE-2022-29130, CVE-2022-29131, CVE-2022-29137, CVE-2022-29139, CVE-2022-29141. May 10, 2022 | CVSS8.8v3.1 | EPSS2.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29127MEDIUM | BitLocker Security Feature Bypass VulnerabilityBitLocker Security Feature Bypass Vulnerability. May 10, 2022 | CVSS4.2v3.1 | EPSS0.805% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29126HIGH | Tablet Windows User Interface Application Core Elevation of Privilege VulnerabilityTablet Windows User Interface Application Core Elevation of Privilege Vulnerability. May 10, 2022 | CVSS7.0v3.1 | EPSS0.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29125HIGH | Windows Push Notifications Apps Elevation of Privilege VulnerabilityWindows Push Notifications Apps Elevation of Privilege Vulnerability. CWE-269May 10, 2022 | CVSS7.0v3.1 | EPSS0.686% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29121MEDIUM | Windows WLAN AutoConfig Service Denial of Service VulnerabilityWindows WLAN AutoConfig Service Denial of Service Vulnerability. CWE-400May 10, 2022 | CVSS6.5v3.1 | EPSS0.884% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29115HIGH | Windows Fax Service Remote Code Execution VulnerabilityWindows Fax Service Remote Code Execution Vulnerability. CWE-94May 10, 2022 | CVSS7.8v3.1 | EPSS2.27% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29114MEDIUM | Windows Print Spooler Information Disclosure VulnerabilityWindows Print Spooler Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-29140. CWE-863May 10, 2022 | CVSS5.5v3.1 | EPSS1.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29113HIGH | Windows Digital Media Receiver Elevation of Privilege VulnerabilityWindows Digital Media Receiver Elevation of Privilege Vulnerability. CWE-362May 10, 2022 | CVSS7.8v3.1 | EPSS0.411% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29112MEDIUM | Windows Graphics Component Information Disclosure VulnerabilityWindows Graphics Component Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-22011, CVE-2022-26934. CWE-668May 10, 2022 | CVSS6.5v3.1 | EPSS3.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29105HIGH | Microsoft Windows Media Foundation Remote Code Execution VulnerabilityMicrosoft Windows Media Foundation Remote Code Execution Vulnerability. May 10, 2022 | CVSS7.8v3.1 | EPSS2.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29104HIGH | Windows Print Spooler Elevation of Privilege VulnerabilityWindows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29132. May 10, 2022 | CVSS7.8v3.1 | EPSS12.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-29103HIGH | Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityWindows Remote Access Connection Manager Elevation of Privilege Vulnerability. May 10, 2022 | CVSS7.8v3.1 | EPSS0.606% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26936MEDIUM | Windows Server Service Information Disclosure VulnerabilityWindows Server Service Information Disclosure Vulnerability. CWE-668May 10, 2022 | CVSS6.5v3.1 | EPSS2.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26935MEDIUM | Windows WLAN AutoConfig Service Information Disclosure VulnerabilityWindows WLAN AutoConfig Service Information Disclosure Vulnerability. CWE-668May 10, 2022 | CVSS6.5v3.1 | EPSS0.987% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26934MEDIUM | Windows Graphics Component Information Disclosure VulnerabilityWindows Graphics Component Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-22011, CVE-2022-29112. May 10, 2022 | CVSS6.5v3.1 | EPSS2.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |