Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 1 of 36
CVE-2019-0708P1CRITICALCVSS 9.8KEVPoCRansomwarev2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+6 more2019-05-16
CVE-2019-0708 [CRITICAL] CWE-416 CVE-2019-0708: A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal S
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
nvd
CVE-2020-1350P1CRITICALCVSS 10.0KEVPoCv2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1350 [CRITICAL] CWE-20 CVE-2020-1350: A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.
nvd
CVE-2020-0601P1HIGHCVSS 8.1KEVPoCRansomwarevversion 1803 (Core Installation)v2019+3 more2020-01-14
CVE-2020-0601 [HIGH] CWE-295 CVE-2020-0601: A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnera
nvd
CVE-2019-1458P1HIGHCVSS 7.8KEVPoCRansomwarev2016v2016 (Core installation)+12 more2019-12-10
CVE-2019-1458 [HIGH] CVE-2019-1458: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1054P1HIGHCVSS 7.8KEVPoCvversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1054 [HIGH] CWE-787 CVE-2020-1054: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
nvd
CVE-2020-0787P1HIGHCVSS 7.8KEVPoCRansomwarevversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0787 [HIGH] CWE-59 CVE-2020-0787: An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Serv
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1405P1HIGHCVSS 7.8KEVPoCRansomwarev2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-11-12
CVE-2019-1405 [HIGH] CWE-269 CVE-2019-1405: An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) servi
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1215P1HIGHCVSS 7.8KEVPoCRansomwarevversion 1803 (Core Installation)v2019+1 more2019-09-11
CVE-2019-1215 [HIGH] CWE-269 CVE-2019-1215: An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.
nvd
CVE-2019-1385P1HIGHCVSS 7.8KEVPoCRansomwarevversion 1803 (Core Installation)v2019+1 more2019-11-12
CVE-2019-1385 [HIGH] CWE-59 CVE-2019-1385: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correct
nvd
CVE-2019-1388P1HIGHCVSS 7.8KEVPoCRansomwarev2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-11-12
CVE-2019-1388 [HIGH] CWE-269 CVE-2019-1388: An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not pr
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1132P1HIGHCVSS 7.8KEVPoCv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+6 more2019-07-15
CVE-2019-1132 [HIGH] CVE-2019-1132: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0683P1HIGHCVSS 7.8KEVPoCvversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0683 [HIGH] CWE-59 CVE-2020-0683: An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process sy
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
nvd
CVE-2019-0863P1HIGHCVSS 7.8KEVPoCv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-05-16
CVE-2019-0863 [HIGH] CVE-2019-0863: An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles file
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0938P1HIGHCVSS 7.8KEVvversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0938 [HIGH] CWE-787 CVE-2020-0938: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manage
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Re
nvd
CVE-2020-0986P1HIGHCVSS 7.8KEVRansomwarevversion 1803 (Core Installation)v2019+3 more2020-06-09
CVE-2020-0986 [HIGH] CWE-787 CVE-2020-0986: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-
nvd
CVE-2019-0903P1HIGHCVSS 8.8KEVv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-05-16
CVE-2019-0903 [HIGH] CVE-2019-0903: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2020-0638P1HIGHCVSS 7.8KEVRansomwarev2019v2019 (Core installation)+1 more2020-01-14
CVE-2020-0638 [HIGH] CWE-59 CVE-2020-0638: An elevation of privilege vulnerability exists in the way the Update Notification Manager handles fi
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1315P1HIGHCVSS 7.8KEVRansomwarev2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-10-10
CVE-2019-1315 [HIGH] CWE-59 CVE-2019-1315: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handl
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.
nvd
CVE-2019-1129P1HIGHCVSS 7.8KEVRansomwarev2012v2012 (Core installation)+7 more2019-07-15
CVE-2019-1129 [HIGH] CWE-59 CVE-2019-1129: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improp
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
nvd
CVE-2019-0880P2HIGHCVSS 7.8KEVv2012v2012 (Core installation)+7 more2019-07-15
CVE-2019-0880 [HIGH] CVE-2019-0880: A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka '
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
nvd
1 / 36Next →