Microsoft Windows 10 Servers vulnerabilities
135 known vulnerabilities affecting microsoft/windows_10_servers.
Total CVEs
135
CISA KEV
7
actively exploited
Public exploits
22
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH77MEDIUM52LOW3
Vulnerabilities
Page 3 of 7
CVE-2018-8634P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-12-12
CVE-2018-8634 [HIGH] CVE-2018-8634: A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to prop
A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory, aka "Microsoft Text-To-Speech Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2018-8423P3HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-10-10
CVE-2018-8423 [HIGH] CWE-119 CVE-2018-8423: A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JE
A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Wi
nvd
CVE-2018-8136P3HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-05-09
CVE-2018-8136 [HIGH] CVE-2018-8136: A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8392P3HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8392 [HIGH] CVE-2018-8392: A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote
A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Serve
nvd
CVE-2019-0538P3HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2019-01-08
CVE-2019-0538 [HIGH] CVE-2019-0538: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2018-8493P3HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-10-10
CVE-2018-8493 [HIGH] CVE-2018-8493: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles frag
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka "Windows TCP/IP Information Disclosure Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8239P3MEDIUMCVSS 5.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8239 [MEDIUM] CWE-200 CVE-2018-8239: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-0959P3HIGHCVSS 7.6vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-05-09
CVE-2018-0959 [HIGH] CWE-20 CVE-2018-0959: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2018-8489P3HIGHCVSS 8.4vversion 1709 (Server Core Installation)2018-10-10
CVE-2018-8489 [HIGH] CWE-20 CVE-2018-8489: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012
nvd
CVE-2018-0956P3HIGHCVSS 7.5vversion 1709 (Server Core Installation)2018-04-12
CVE-2018-0956 [HIGH] CVE-2018-0956: A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys imp
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8251P3HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8251 [HIGH] CWE-787 CVE-2018-8251: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media Foundation Memory Corruption Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-0965P3HIGHCVSS 8.4vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-0965 [HIGH] CWE-20 CVE-2018-0965: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8439.
nvd
CVE-2019-0550P3HIGHCVSS 8.4vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2019-01-08
CVE-2019-0550 [HIGH] CWE-20 CVE-2019-0550: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. This CVE ID is unique from CVE-2019-0551.
nvd
CVE-2018-8226P3HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8226 [HIGH] CVE-2018-8226: A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys imp
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8206P3HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-07-11
CVE-2018-8206 [HIGH] CVE-2018-8206: A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP
A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP) connections, aka "Windows FTP Server Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Ser
nvd
CVE-2018-8219P3HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8219 [HIGH] CVE-2018-8219: An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to p
An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8335P3HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8335 [HIGH] CVE-2018-8335: A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacke
A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8218P3HIGHCVSS 7.7vversion 1709 (Server Core Installation)2018-06-14
CVE-2018-8218 [HIGH] CWE-20 CVE-2018-8218: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows 10, Windows 10 Servers.
nvd
CVE-2018-8209P3HIGHCVSS 8.0vversion 1709 (Server Core Installation)2018-06-14
CVE-2018-8209 [HIGH] CWE-200 CVE-2018-8209: An information disclosure vulnerability exists when Windows allows a normal user to access the Wirel
An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of an administrative user, aka "Windows Wireless Network Profile Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8449P4LOWCVSS 3.3PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-09-13
CVE-2018-8449 [LOW] CWE-367 CVE-2018-8449: A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Dev
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd