cbcvebase.

Microsoft Windows Server vulnerabilities

705 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4

Vulnerabilities

Page 10 of 36
CVE-2020-0708P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0708 [HIGH] CVE-2020-0708: A remote code execution vulnerability exists when the Windows Imaging Library improperly handles mem A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.To exploit this vulnerability, an attacker would first have to coerce a victim to open a specially crafted file.The security update addresses the vulnerability by correcting how the Windows Imaging Library handles memory., aka 'Windows Imaging Library Remote
nvd
CVE-2019-0688P3HIGHCVSS 7.5v2012v2012 (Core installation)+8 more2019-04-09
CVE-2019-0688 [HIGH] CWE-327 CVE-2019-0688: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles frag An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
nvd
CVE-2020-1113P3HIGHCVSS 7.5vversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1113 [HIGH] CWE-295 CVE-2020-1113: A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1406P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-11-12
CVE-2019-1406 [HIGH] CVE-2019-1406: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.
nvd
CVE-2018-0895P4MEDIUMCVSS 4.7PoCv17092018-03-14
CVE-2018-0895 [MEDIUM] CVE-2018-0895: The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and R The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disc
nvd
CVE-2019-1240P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1240 [HIGH] CVE-2019-1240: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2018-0901P4MEDIUMCVSS 4.7PoCv17092018-03-14
CVE-2018-0901 [MEDIUM] CVE-2018-0901: The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and R The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disc
nvd
CVE-2018-0897P4MEDIUMCVSS 4.7PoCv17092018-03-14
CVE-2018-0897 [MEDIUM] CVE-2018-0897: The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and R The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disc
nvd
CVE-2018-0894P4MEDIUMCVSS 4.7PoCv17092018-03-14
CVE-2018-0894 [MEDIUM] CVE-2018-0894: The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and R The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disc
nvd
CVE-2022-21974P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-21974 [HIGH] CVE-2022-21974: Roaming Security Rights Management Services Remote Code Execution Vulnerability Roaming Security Rights Management Services Remote Code Execution Vulnerability
nvd
CVE-2020-1118P3HIGHCVSS 7.5vversion 1803 (Core Installation)v2019+1 more2020-05-21
CVE-2020-1118 [HIGH] CVE-2020-1118: A denial of service vulnerability exists in the Windows implementation of Transport Layer Security ( A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges, aka 'Microsoft Windows Transport Layer Security Denial of Service Vulnerability'.
nvd
CVE-2020-1208P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1208 [HIGH] CVE-2020-1208: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1236.
nvd
CVE-2020-0889P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0889 [HIGH] CVE-2020-0889: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0953, CVE-2020-0959, CVE-2020-0960, CVE-2020-0988, CVE-2020-0992, CVE-2020-0994, CVE-2020-0995, CVE-2020-0999, CVE-2020-1008.
nvd
CVE-2019-1389P3HIGHCVSS 8.4vversion 1803 (Core Installation)v2019+1 more2019-11-12
CVE-2019-1389 [HIGH] CWE-20 CVE-2019-1389: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1397, CVE-2019-1398.
nvd
CVE-2022-22000P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-22000 [HIGH] CVE-2022-22000: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-0637P3HIGHCVSS 7.5vversion 1709 (Core Installation)vversion 1803 (Core Installation)+2 more2019-03-05
CVE-2019-0637 [HIGH] CVE-2019-0637: A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies fi A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, aka 'Windows Defender Firewall Security Feature Bypass Vulnerability'.
nvd
CVE-2022-21843P3HIGHCVSS 7.5v20h2v20222022-01-11
CVE-2022-21843 [HIGH] CVE-2022-21843: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2021-43233P3HIGHCVSS 7.5v20h2v20222021-12-15
CVE-2021-43233 [HIGH] CVE-2021-43233: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2021-40456P3HIGHCVSS 7.5v20h22021-10-13
CVE-2021-40456 [HIGH] CWE-863 CVE-2021-40456: Windows AD FS Security Feature Bypass Vulnerability Windows AD FS Security Feature Bypass Vulnerability
nvd
CVE-2017-11788P3HIGHCVSS 7.5v17092017-11-15
CVE-2017-11788 [HIGH] CVE-2017-11788: Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remotely send specially crafted messages that could cause a denial of service against the system due to i
nvd
Microsoft Windows Server vulnerabilities | cvebase