cbcvebase.

Microsoft Windows Server vulnerabilities

670 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4

Vulnerabilities

Page 10 of 34
CVE-2018-0897P4MEDIUMCVSS 4.7PoCv17092018-03-14
CVE-2018-0897 [MEDIUM] CVE-2018-0897: The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and R The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disc
nvd
CVE-2018-0894P4MEDIUMCVSS 4.7PoCv17092018-03-14
CVE-2018-0894 [MEDIUM] CVE-2018-0894: The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and R The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Kernel Information Disc
nvd
CVE-2022-21974P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-21974 [HIGH] CVE-2022-21974: Roaming Security Rights Management Services Remote Code Execution Vulnerability Roaming Security Rights Management Services Remote Code Execution Vulnerability
nvd
CVE-2019-1424P3HIGHCVSS 8.1v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-11-12
CVE-2019-1424 [HIGH] CVE-2019-1424: A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure com A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
nvd
CVE-2020-1208P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1208 [HIGH] CVE-2020-1208: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1236.
nvd
CVE-2017-11788P3HIGHCVSS 7.5v17092017-11-15
CVE-2017-11788 [HIGH] CVE-2017-11788: Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remotely send specially crafted messages that could cause a denial of service against the system due to i
nvd
CVE-2020-0889P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0889 [HIGH] CVE-2020-0889: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0953, CVE-2020-0959, CVE-2020-0960, CVE-2020-0988, CVE-2020-0992, CVE-2020-0994, CVE-2020-0995, CVE-2020-0999, CVE-2020-1008.
nvd
CVE-2022-22000P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-22000 [HIGH] CVE-2022-22000: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-0637P3HIGHCVSS 7.5vversion 1709 (Core Installation)vversion 1803 (Core Installation)+2 more2019-03-05
CVE-2019-0637 [HIGH] CVE-2019-0637: A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies fi A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connections, aka 'Windows Defender Firewall Security Feature Bypass Vulnerability'.
nvd
CVE-2022-21843P3HIGHCVSS 7.5v20h2v20222022-01-11
CVE-2022-21843 [HIGH] CVE-2022-21843: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2021-40456P3HIGHCVSS 7.5v20h22021-10-13
CVE-2021-40456 [HIGH] CWE-863 CVE-2021-40456: Windows AD FS Security Feature Bypass Vulnerability Windows AD FS Security Feature Bypass Vulnerability
nvd
CVE-2021-43233P3HIGHCVSS 7.5v20h2v20222021-12-15
CVE-2021-43233 [HIGH] CVE-2021-43233: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-21994P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-21994 [HIGH] CVE-2022-21994: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-24507P3HIGHCVSS 7.8v20h22022-03-09
CVE-2022-24507 [HIGH] CVE-2022-24507: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-21989P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-21989 [HIGH] CVE-2022-21989: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-26931P3HIGHCVSS 7.5v20222022-05-10
CVE-2022-26931 [HIGH] CVE-2022-26931: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2019-1453P3HIGHCVSS 7.5vversion 1803 (Core Installation)v2019+10 more2019-12-10
CVE-2019-1453 [HIGH] CVE-2019-1453: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2022-21878P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21878 [HIGH] CVE-2022-21878: Windows Geolocation Service Remote Code Execution Vulnerability Windows Geolocation Service Remote Code Execution Vulnerability
nvd
CVE-2022-21992P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-21992 [HIGH] CVE-2022-21992: Windows Mobile Device Management Remote Code Execution Vulnerability Windows Mobile Device Management Remote Code Execution Vulnerability
nvd
CVE-2022-29115P3HIGHCVSS 7.8v20h2v20222022-05-10
CVE-2022-29115 [HIGH] CVE-2022-29115: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
Microsoft Windows Server vulnerabilities | cvebase