Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Update Microsoft/Windows 10 Version 1507 to 10.0.10240.19003; Microsoft/Windows 10 Version 1607 to 10.0.14393.4530; Microsoft/Windows 10 Version 1809 to 10.0.17763.2061; Microsoft/Windows 10 Version 1909 to 10.0.18363.1679; Microsoft/Windows 10 Version 2004 to 10.0.19041.1110; Microsoft/Windows 10 Version 20H2 to 10.0.19042.1110; Microsoft/Windows 10 Version 21H1 to 10.0.19043.1110; Microsoft/Windows 8.1 to 6.3.9600.20069; Microsoft/Windows Server 2012 R2 to 6.3.9600.20069; Microsoft/Windows Server 2012 R2 (Server Core installation) to 6.3.9600.20069; Microsoft/Windows Server 2016 to 10.0.14393.4530; Microsoft/Windows Server 2016 (Server Core installation) to 10.0.14393.4530; Microsoft/Windows Server 2019 to 10.0.17763.2061; Microsoft/Windows Server 2019 (Server Core installation) to 10.0.17763.2061; Microsoft/Windows Server version 2004 to 10.0.19041.1110; Microsoft/Windows Server version 20H2 to 10.0.19042.1110 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanWindows Kernel Elevation of Privilege Vulnerability affects Microsoft/Windows 10 Version 1507 (generic), Microsoft/Windows 10 Version 1607 (generic), Microsoft/Windows 10 Version 1809 (generic), Microsoft/Windows 10 Version 1909 (generic), Microsoft/Windows 10 Version 2004 (generic), Microsoft/Windows 10 Version 20H2 (generic), Microsoft/Windows 10 Version 21H1 (generic), Microsoft/Windows 8.1 (generic), Microsoft/Windows Server 2012 R2 (generic), Microsoft/Windows Server 2012 R2 (Server Core installation) (generic), Microsoft/Windows Server 2016 (generic), Microsoft/Windows Server 2016 (Server Core installation) (generic), Microsoft/Windows Server 2019 (generic), Microsoft/Windows Server 2019 (Server Core installation) (generic), Microsoft/Windows Server version 2004 (generic), Microsoft/Windows Server version 20H2 (generic). Severity is high. This vulnerability is known to be exploited in the wild. Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Update Microsoft/Windows 10 Version 1507 to 10.0.10240.19003; Microsoft/Windows 10 Version 1607 to 10.0.14393.4530; Microsoft/Windows 10 Version 1809 to 10.0.17763.2061; Microsoft/Windows 10 Version 1909 to 10.0.18363.1679; Microsoft/Windows 10 Version 2004 to 10.0.19041.1110; Microsoft/Windows 10 Version 20H2 to 10.0.19042.1110; Microsoft/Windows 10 Version 21H1 to 10.0.19043.1110; Microsoft/Windows 8.1 to 6.3.9600.20069; Microsoft/Windows Server 2012 R2 to 6.3.9600.20069; Microsoft/Windows Server 2012 R2 (Server Core installation) to 6.3.9600.20069; Microsoft/Windows Server 2016 to 10.0.14393.4530; Microsoft/Windows Server 2016 (Server Core installation) to 10.0.14393.4530; Microsoft/Windows Server 2019 to 10.0.17763.2061; Microsoft/Windows Server 2019 (Server Core installation) to 10.0.17763.2061; Microsoft/Windows Server version 2004 to 10.0.19041.1110; Microsoft/Windows Server version 20H2 to 10.0.19042.1110 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanWindows Kernel Elevation of Privilege Vulnerability affects Microsoft/Windows 10 Version 1507 (generic), Microsoft/Windows 10 Version 1607 (generic), Microsoft/Windows 10 Version 1809 (generic), Microsoft/Windows 10 Version 1909 (generic), Microsoft/Windows 10 Version 2004 (generic), Microsoft/Windows 10 Version 20H2 (generic), Microsoft/Windows 10 Version 21H1 (generic), Microsoft/Windows 8.1 (generic), Microsoft/Windows Server 2012 R2 (generic), Microsoft/Windows Server 2012 R2 (Server Core installation) (generic), Microsoft/Windows Server 2016 (generic), Microsoft/Windows Server 2016 (Server Core installation) (generic), Microsoft/Windows Server 2019 (generic), Microsoft/Windows Server 2019 (Server Core installation) (generic), Microsoft/Windows Server version 2004 (generic), Microsoft/Windows Server version 20H2 (generic). Severity is high. This vulnerability is known to be exploited in the wild. Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Microsoft/Windows 10 Version 1507generic | >=10.0.0 <10.0.10240.19003 | 10.0.10240.19003 |
| Microsoft/Windows 10 Version 1607generic | >=10.0.0 <10.0.14393.4530 | 10.0.14393.4530 |
| Microsoft/Windows 10 Version 1809generic | >=10.0.0 <10.0.17763.2061 | 10.0.17763.2061 |
| Microsoft/Windows 10 Version 1909generic | >=10.0.0 <10.0.18363.1679 | 10.0.18363.1679 |
| Microsoft/Windows 10 Version 2004generic | >=10.0.0 <10.0.19041.1110 | 10.0.19041.1110 |
| Microsoft/Windows 10 Version 20H2generic | >=10.0.0 <10.0.19042.1110 | 10.0.19042.1110 |
| Microsoft/Windows 10 Version 21H1generic | >=10.0.0 <10.0.19043.1110 | 10.0.19043.1110 |
| Microsoft/Windows 8.1generic | >=6.3.0 <6.3.9600.20069 | 6.3.9600.20069 |
| Microsoft/Windows Server 2012 R2generic | >=6.3.0 <6.3.9600.20069 | 6.3.9600.20069 |
| Microsoft/Windows Server 2012 R2 (Server Core installation)generic | >=6.3.0 <6.3.9600.20069 | 6.3.9600.20069 |
| Microsoft/Windows Server 2016generic | >=10.0.0 <10.0.14393.4530 | 10.0.14393.4530 |
| Microsoft/Windows Server 2016 (Server Core installation)generic | >=10.0.0 <10.0.14393.4530 | 10.0.14393.4530 |
| Microsoft/Windows Server 2019generic | >=10.0.0 <10.0.17763.2061 | 10.0.17763.2061 |
| Microsoft/Windows Server 2019 (Server Core installation)generic | >=10.0.0 <10.0.17763.2061 | 10.0.17763.2061 |
| Microsoft/Windows Server version 2004generic | >=10.0.0 <10.0.19041.1110 | 10.0.19041.1110 |
| Microsoft/Windows Server version 20H2generic | >=10.0.0 <10.0.19042.1110 | 10.0.19042.1110 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|---|---|
| Microsoft/Windows 10 Version 1507generic | >=10.0.0 <10.0.10240.19003 | 10.0.10240.19003 |
| Microsoft/Windows 10 Version 1607generic | >=10.0.0 <10.0.14393.4530 | 10.0.14393.4530 |
| Microsoft/Windows 10 Version 1809generic | >=10.0.0 <10.0.17763.2061 | 10.0.17763.2061 |
| Microsoft/Windows 10 Version 1909generic | >=10.0.0 <10.0.18363.1679 | 10.0.18363.1679 |
| Microsoft/Windows 10 Version 2004generic | >=10.0.0 <10.0.19041.1110 | 10.0.19041.1110 |
| Microsoft/Windows 10 Version 20H2generic | >=10.0.0 <10.0.19042.1110 | 10.0.19042.1110 |
| Microsoft/Windows 10 Version 21H1generic | >=10.0.0 <10.0.19043.1110 | 10.0.19043.1110 |
| Microsoft/Windows 8.1generic | >=6.3.0 <6.3.9600.20069 | 6.3.9600.20069 |
| Microsoft/Windows Server 2012 R2generic | >=6.3.0 <6.3.9600.20069 | 6.3.9600.20069 |
| Microsoft/Windows Server 2012 R2 (Server Core installation)generic | >=6.3.0 <6.3.9600.20069 | 6.3.9600.20069 |
| Microsoft/Windows Server 2016generic | >=10.0.0 <10.0.14393.4530 | 10.0.14393.4530 |
| Microsoft/Windows Server 2016 (Server Core installation)generic | >=10.0.0 <10.0.14393.4530 | 10.0.14393.4530 |
| Microsoft/Windows Server 2019generic | >=10.0.0 <10.0.17763.2061 | 10.0.17763.2061 |
| Microsoft/Windows Server 2019 (Server Core installation)generic | >=10.0.0 <10.0.17763.2061 | 10.0.17763.2061 |
| Microsoft/Windows Server version 2004generic | >=10.0.0 <10.0.19041.1110 | 10.0.19041.1110 |
| Microsoft/Windows Server version 20H2generic | >=10.0.0 <10.0.19042.1110 | 10.0.19042.1110 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard