Microsoft Windows 10 Servers vulnerabilities
135 known vulnerabilities affecting microsoft/windows_10_servers.
Total CVEs
135
CISA KEV
7
actively exploited
Public exploits
22
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH77MEDIUM52LOW3
Vulnerabilities
Page 2 of 7
CVE-2018-8584P3HIGHCVSS 7.8PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-11-14
CVE-2018-8584 [HIGH] CWE-367 CVE-2018-8584: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2018-8411P3HIGHCVSS 7.8PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-10-10
CVE-2018-8411 [HIGH] CWE-732 CVE-2018-8411: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0570P3HIGHCVSS 7.8PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2019-01-08
CVE-2019-0570 [HIGH] CWE-416 CVE-2019-0570: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8626P2CRITICALCVSS 9.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-12-12
CVE-2018-8626 [CRITICAL] CWE-787 CVE-2018-8626: A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they f
A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8495P3HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-10-10
CVE-2018-8495 [HIGH] CWE-22 CVE-2018-8495: A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Window
A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8256P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-11-14
CVE-2018-8256 [HIGH] CVE-2018-8256: A remote code execution vulnerability exists when PowerShell improperly handles specially crafted fi
A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows
nvd
CVE-2018-8450P2HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-11-14
CVE-2018-8450 [HIGH] CWE-404 CVE-2018-8450: A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Win
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8344P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8344 [HIGH] CWE-94 CVE-2018-8344: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2018-8349P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8349 [HIGH] CWE-502 CVE-2018-8349: A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properl
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2018-8494P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-10-10
CVE-2018-8494 [HIGH] CWE-611 CVE-2018-8494: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Win
nvd
CVE-2018-8332P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8332 [HIGH] CVE-2018-8332: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows
nvd
CVE-2018-8208P3HIGHCVSS 7.0PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8208 [HIGH] CVE-2018-8208: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly mana
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8214.
nvd
CVE-2018-8134P3HIGHCVSS 7.0PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-05-09
CVE-2018-8134 [HIGH] CVE-2018-8134: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2018-0982P3HIGHCVSS 7.0PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-0982 [HIGH] CWE-732 CVE-2018-0982: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8225P3HIGHCVSS 8.1vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8225 [HIGH] CVE-2018-8225: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it
A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2018-8350P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8350 [HIGH] CVE-2018-8350: A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles o
A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
nvd
CVE-2018-8468P3MEDIUMCVSS 4.7PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8468 [MEDIUM] CVE-2018-8468: An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8475P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8475 [HIGH] CVE-2018-8475: A remote code execution vulnerability exists when Windows does not properly handle specially crafted
A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8231P3HIGHCVSS 8.1vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8231 [HIGH] CVE-2018-8231: A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles
A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory, aka "HTTP Protocol Stack Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8210P3HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8210 [HIGH] CWE-404 CVE-2018-8210: A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8213.
nvd