Microsoft Windows 10 Servers vulnerabilities
135 known vulnerabilities affecting microsoft/windows_10_servers.
Total CVEs
135
CISA KEV
7
actively exploited
Public exploits
22
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH77MEDIUM52LOW3
Vulnerabilities
Page 1 of 7
CVE-2018-8174P1HIGHCVSS 7.5KEVPoCRansomwarevversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-05-09
CVE-2018-8174 [HIGH] CWE-787 CVE-2018-8174: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windo
nvd
CVE-2018-8453P1HIGHCVSS 7.8KEVPoCRansomwarevversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-10-10
CVE-2018-8453 [HIGH] CVE-2018-8453: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2,
nvd
CVE-2018-8120P1HIGHCVSS 7.0KEVPoCRansomwarevversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-05-09
CVE-2018-8120 [HIGH] CWE-404 CVE-2018-8120: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
nvd
CVE-2018-8414P1HIGHCVSS 8.8KEVPoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8414 [HIGH] CWE-20 CVE-2018-8414: A remote code execution vulnerability exists when the Windows Shell does not properly validate file
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
nvd
CVE-2018-8639P1HIGHCVSS 7.8KEVPoCRansomwarevversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-12-12
CVE-2018-8639 [HIGH] CWE-404 CVE-2018-8639: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server
nvd
CVE-2018-8440P1HIGHCVSS 7.8KEVPoCRansomwarevversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8440 [HIGH] CVE-2018-8440: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Wind
nvd
CVE-2018-8611P1HIGHCVSS 7.8KEVPoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-12-12
CVE-2018-8611 [HIGH] CWE-404 CVE-2018-8611: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2018-8140P1MEDIUMCVSS 6.8ExploitedRansomwarevversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8140 [MEDIUM] CVE-2018-8140: An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services
An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10.
nvd
CVE-2018-8514P2MEDIUMCVSS 5.5Exploitedvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-12-12
CVE-2018-8514 [MEDIUM] CWE-665 CVE-2018-8514: An information disclosure vulnerability exists when Remote Procedure Call runtime improperly initial
An information disclosure vulnerability exists when Remote Procedure Call runtime improperly initializes objects in memory, aka "Remote Procedure Call runtime Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2018-8595P2MEDIUMCVSS 6.5Exploitedvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-12-12
CVE-2018-8595 [MEDIUM] CVE-2018-8595: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2018-8637P2MEDIUMCVSS 5.5Exploitedvversion 1803 (Server Core Installation)2018-12-12
CVE-2018-8637 [MEDIUM] CVE-2018-8637: An information disclosure vulnerability exists in Windows kernel that could allow an attacker to ret
An information disclosure vulnerability exists in Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (KASLR) bypass, aka "Win32k Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
nvd
CVE-2018-8544P2HIGHCVSS 8.8PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-11-14
CVE-2018-8544 [HIGH] CWE-416 CVE-2018-8544: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2018-8413P2HIGHCVSS 7.8PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-10-10
CVE-2018-8413 [HIGH] CVE-2018-8413: A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress f
A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0547P2CRITICALCVSS 9.8vversion 1803 (Server Core Installation)2019-01-08
CVE-2019-0547 [CRITICAL] CWE-787 CVE-2019-0547: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.
nvd
CVE-2018-8476P2CRITICALCVSS 9.8vversion 1803 (Server Core Installation)2018-11-14
CVE-2018-8476 [CRITICAL] CWE-119 CVE-2018-8476: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows Server 2008, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows Server 2008
nvd
CVE-2019-0571P3HIGHCVSS 7.8PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2019-01-08
CVE-2019-0571 [HIGH] CWE-706 CVE-2019-0571: An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly hand
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0572, CVE-2019-0573, CVE-2019-0574.
nvd
CVE-2018-0952P3HIGHCVSS 7.8PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-0952 [HIGH] CVE-2018-0952: An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file c
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.
nvd
CVE-2018-8420P2HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8420 [HIGH] CWE-611 CVE-2018-8420: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 S
nvd
CVE-2019-0552P3HIGHCVSS 8.8PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2019-01-08
CVE-2019-0552 [HIGH] CWE-863 CVE-2019-0552: An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privil
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8410P3HIGHCVSS 7.8PoCvversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8410 [HIGH] CWE-404 CVE-2018-8410: An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles regist
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Server
nvd
1 / 7Next →