Microsoft Windows 10 Servers vulnerabilities
206 known vulnerabilities affecting microsoft/windows_10_servers.
Total CVEs
206
CISA KEV
9
actively exploited
Public exploits
30
Exploited in wild
13
Severity breakdown
CRITICAL3HIGH111MEDIUM88LOW4
Vulnerabilities
Page 8 of 11
CVE-2018-8210HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8210 [HIGH] CWE-404 CVE-2018-8210: A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8213.
cvelistv5nvd
CVE-2018-8226HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8226 [HIGH] CVE-2018-8226: A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys imp
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-0982HIGHCVSS 7.0PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-0982 [HIGH] CWE-732 CVE-2018-0982: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8218HIGHCVSS 7.7vversion 1709 (Server Core Installation)2018-06-14
CVE-2018-8218 [HIGH] CWE-20 CVE-2018-8218: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8251HIGHCVSS 7.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8251 [HIGH] CWE-787 CVE-2018-8251: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media Foundation Memory Corruption Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8169HIGHCVSS 7.0vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8169 [HIGH] CWE-404 CVE-2018-8169: An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library
An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory, aka "HIDParser Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
cvelistv5nvd
CVE-2018-8208HIGHCVSS 7.0PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8208 [HIGH] CVE-2018-8208: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly mana
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8214.
cvelistv5nvd
CVE-2018-8214HIGHCVSS 7.0PoCvversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8214 [HIGH] CVE-2018-8214: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Brid
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8208.
cvelistv5
CVE-2018-8231HIGHCVSS 8.1vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8231 [HIGH] CVE-2018-8231: A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles
A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory, aka "HTTP Protocol Stack Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8213HIGHCVSS 7.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8213 [HIGH] CVE-2018-8213: A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8210.
cvelistv5
CVE-2018-8233HIGHCVSS 7.8vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8233 [HIGH] CWE-404 CVE-2018-8233: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8212MEDIUMCVSS 4.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8212 [MEDIUM] CVE-2018-8212: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID i
cvelistv5
CVE-2018-8239MEDIUMCVSS 5.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8239 [MEDIUM] CWE-200 CVE-2018-8239: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8140MEDIUMCVSS 6.8vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8140 [MEDIUM] CVE-2018-8140: An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services
An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status, aka "Cortana Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10.
cvelistv5nvd
CVE-2018-8215MEDIUMCVSS 4.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8215 [MEDIUM] CVE-2018-8215: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID i
cvelistv5
CVE-2018-8221MEDIUMCVSS 4.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8221 [MEDIUM] CVE-2018-8221: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID i
cvelistv5
CVE-2018-1040MEDIUMCVSS 5.3vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-1040 [MEDIUM] CVE-2018-1040: A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs
A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Windows Code Integrity Module Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows
cvelistv5nvd
CVE-2018-8205MEDIUMCVSS 5.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8205 [MEDIUM] CVE-2018-8205: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
cvelistv5nvd
CVE-2018-8201MEDIUMCVSS 4.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8201 [MEDIUM] CVE-2018-8201: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8211, CVE-2018-8212, CVE-20
cvelistv5nvd
CVE-2018-8175MEDIUMCVSS 6.5vversion 1709 (Server Core Installation)vversion 1803 (Server Core Installation)2018-06-14
CVE-2018-8175 [MEDIUM] CVE-2018-8175: An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV
An denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory, aka "WEBDAV Denial of Service Vulnerability." This affects Windows 10 Servers, Windows 10.
cvelistv5nvd