Microsoft Windows 10 Servers vulnerabilities
206 known vulnerabilities affecting microsoft/windows_10_servers.
Total CVEs
206
CISA KEV
9
actively exploited
Public exploits
30
Exploited in wild
13
Severity breakdown
CRITICAL3HIGH111MEDIUM88LOW4
Vulnerabilities
Page 7 of 11
CVE-2018-8345HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8345 [HIGH] CVE-2018-8345: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
cvelistv5
CVE-2018-8340MEDIUMCVSS 6.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8340 [MEDIUM] CVE-2018-8340: A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) imp
A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authentication requests, aka "AD FS Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows Server 2012 R2, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8341MEDIUMCVSS 4.7vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8341 [MEDIUM] CWE-200 CVE-2018-8341: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE I
cvelistv5nvd
CVE-2018-8204MEDIUMCVSS 5.3vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8204 [MEDIUM] CVE-2018-8204: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID i
cvelistv5
CVE-2018-8394MEDIUMCVSS 6.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8394 [MEDIUM] CWE-200 CVE-2018-8394: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Window
cvelistv5nvd
CVE-2018-8398MEDIUMCVSS 6.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8398 [MEDIUM] CVE-2018-8398: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Inform
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows S
cvelistv5
CVE-2018-8200MEDIUMCVSS 5.3vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8200 [MEDIUM] CVE-2018-8200: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8204.
cvelistv5nvd
CVE-2018-8348MEDIUMCVSS 4.7vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-08-15
CVE-2018-8348 [MEDIUM] CVE-2018-8348: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosur
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Win
cvelistv5
CVE-2018-8282HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-07-11
CVE-2018-8282 [HIGH] CWE-404 CVE-2018-8282: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Win
cvelistv5nvd
CVE-2018-8206HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-07-11
CVE-2018-8206 [HIGH] CVE-2018-8206: A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP
A denial of service vulnerability exists when Windows improperly handles File Transfer Protocol (FTP) connections, aka "Windows FTP Server Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Ser
cvelistv5nvd
CVE-2018-8313HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-07-11
CVE-2018-8313 [HIGH] CVE-2018-8313: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulner
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID i
cvelistv5
CVE-2018-8304MEDIUMCVSS 5.9vversion 1709 (Server Core Installation)2018-07-11
CVE-2018-8304 [MEDIUM] CVE-2018-8304: A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fail
A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows
cvelistv5nvd
CVE-2018-8307MEDIUMCVSS 5.3vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-07-11
CVE-2018-8307 [MEDIUM] CVE-2018-8307: A security feature bypass vulnerability exists when Microsoft WordPad improperly handles embedded OL
A security feature bypass vulnerability exists when Microsoft WordPad improperly handles embedded OLE objects, aka "WordPad Security Feature Bypass Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8308MEDIUMCVSS 6.6vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-07-11
CVE-2018-8308 [MEDIUM] CWE-404 CVE-2018-8308: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Win
cvelistv5nvd
CVE-2018-8309MEDIUMCVSS 5.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-07-11
CVE-2018-8309 [MEDIUM] CVE-2018-8309: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8222MEDIUMCVSS 5.3vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-07-11
CVE-2018-8222 [MEDIUM] CVE-2018-8222: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8225HIGHCVSS 8.1vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8225 [HIGH] CVE-2018-8225: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it
A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
cvelistv5nvd
CVE-2018-1036HIGHCVSS 7.0vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-1036 [HIGH] CWE-732 CVE-2018-1036: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8209HIGHCVSS 8.0vversion 1709 (Server Core Installation)2018-06-14
CVE-2018-8209 [HIGH] CWE-200 CVE-2018-8209: An information disclosure vulnerability exists when Windows allows a normal user to access the Wirel
An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of an administrative user, aka "Windows Wireless Network Profile Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8219HIGHCVSS 8.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8219 [HIGH] CVE-2018-8219: An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to p
An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels, aka "Hypervisor Code Integrity Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
cvelistv5nvd