cbcvebase.

Microsoft Windows Server vulnerabilities

705 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4

Vulnerabilities

Page 12 of 36
CVE-2022-21905P3HIGHCVSS 8.0v20h2v20222022-01-11
CVE-2022-21905 [HIGH] CVE-2022-21905: Windows Hyper-V Security Feature Bypass Vulnerability Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2019-0727P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-05-16
CVE-2019-0727 [HIGH] CVE-2019-0727: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Vi An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Diagnostic Hub Standard Collector, Visual Studio Standard Collector Elevation of Privilege Vulnerab
nvd
CVE-2022-21912P3HIGHCVSS 7.8v20h22022-01-11
CVE-2022-21912 [HIGH] CVE-2022-21912: DirectX Graphics Kernel Remote Code Execution Vulnerability DirectX Graphics Kernel Remote Code Execution Vulnerability
nvd
CVE-2022-24537P3HIGHCVSS 7.8v20h22022-04-15
CVE-2022-24537 [HIGH] CWE-362 CVE-2022-24537: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2019-0865P3HIGHCVSS 7.5vversion 1803 (Core Installation)v2019+1 more2019-07-15
CVE-2019-0865 [HIGH] CVE-2019-0865: A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digita A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures., aka 'SymCrypt Denial of Service Vulnerability
nvd
CVE-2020-1212P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1212 [HIGH] CVE-2020-1212: An elevation of privilege vulnerability exists when an OLE Automation component improperly handles m An elevation of privilege vulnerability exists when an OLE Automation component improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'OLE Automation Elevation of Privilege Vulnerability'.
nvd
CVE-2022-29105P3HIGHCVSS 7.8v20222022-05-10
CVE-2022-29105 [HIGH] CVE-2022-29105: Microsoft Windows Media Foundation Remote Code Execution Vulnerability Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2021-40465P3HIGHCVSS 7.8v20h22021-10-13
CVE-2021-40465 [HIGH] CVE-2021-40465: Windows Text Shaping Remote Code Execution Vulnerability Windows Text Shaping Remote Code Execution Vulnerability
nvd
CVE-2020-0965P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0965 [HIGH] CVE-2020-0965: A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handl A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'.
nvd
CVE-2021-43232P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43232 [HIGH] CVE-2021-43232: Windows Event Tracing Remote Code Execution Vulnerability Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2022-23284P3HIGHCVSS 7.2v20h2v20222022-03-09
CVE-2022-23284 [HIGH] CVE-2022-23284: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2019-9510P3HIGHCVSS 7.8≥ 2019, < 2019*2020-01-15
CVE-2019-9510 [HIGH] CWE-288 CVE-2019-9510: A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow aut A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen. Should a network anomaly trigger a temporary RDP disconnect, Automatic Reconnection of the RDP session will be restored to an unlock
nvd
CVE-2022-21895P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21895 [HIGH] CWE-59 CVE-2022-21895: Windows User Profile Service Elevation of Privilege Vulnerability Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21995P3HIGHCVSS 7.9v20h2v20222022-02-09
CVE-2022-21995 [HIGH] CVE-2022-21995: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2022-21897P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21897 [HIGH] CVE-2022-21897: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21916P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21916 [HIGH] CVE-2022-21916: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21879P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21879 [HIGH] CVE-2022-21879: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-0810P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-03-12
CVE-2020-0810 [HIGH] CVE-2020-0810: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Vi An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system.An attacker could then run a specially crafted application that could exploit the vulnerability and take
nvd
CVE-2021-43238P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43238 [HIGH] CWE-59 CVE-2021-43238: Windows Remote Access Elevation of Privilege Vulnerability Windows Remote Access Elevation of Privilege Vulnerability
nvd
CVE-2020-1272P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-06-09
CVE-2020-1272 [HIGH] CVE-2020-1272: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE
nvd
Microsoft Windows Server vulnerabilities | cvebase