cbcvebase.

Microsoft Windows Server vulnerabilities

705 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4

Vulnerabilities

Page 14 of 36
CVE-2019-1269P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-09-11
CVE-2019-1269 [HIGH] CVE-2019-1269: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1272.
nvd
CVE-2021-26441P3HIGHCVSS 7.8v20h22021-10-13
CVE-2021-26441 [HIGH] CWE-269 CVE-2021-26441: Storage Spaces Controller Elevation of Privilege Vulnerability Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2020-0641P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-01-14
CVE-2020-0641 [HIGH] CVE-2020-0641: An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.
nvd
CVE-2021-43247P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43247 [HIGH] CWE-787 CVE-2021-43247: Windows TCP/IP Driver Elevation of Privilege Vulnerability Windows TCP/IP Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-0727P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-02-11
CVE-2020-0727 [HIGH] CVE-2020-0727: An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Ser An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1232P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-09-11
CVE-2019-1232 [HIGH] CVE-2019-1232: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka 'Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1254P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1254 [HIGH] CVE-2020-1254: An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly han An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly handles class object members.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Modules Installer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1354P3HIGHCVSS 7.8v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1354 [HIGH] CVE-2020-1354: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1430.
nvd
CVE-2020-1271P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+6 more2020-06-09
CVE-2020-1271 [HIGH] CVE-2020-1271: An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles fi An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1396P3HIGHCVSS 7.8v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1396 [HIGH] CVE-2020-1396: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0844P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+8 more2020-03-12
CVE-2020-0844 [HIGH] CVE-2020-0844: An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
nvd
CVE-2022-21873P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21873 [HIGH] CVE-2022-21873: Tile Data Repository Elevation of Privilege Vulnerability Tile Data Repository Elevation of Privilege Vulnerability
nvd
CVE-2022-21861P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21861 [HIGH] CVE-2022-21861: Task Flow Data Engine Elevation of Privilege Vulnerability Task Flow Data Engine Elevation of Privilege Vulnerability
nvd
CVE-2022-21834P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21834 [HIGH] CVE-2022-21834: Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-40443P3HIGHCVSS 7.8v20h22021-10-13
CVE-2021-40443 [HIGH] CWE-269 CVE-2021-40443: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-24459P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-24459 [HIGH] CVE-2022-24459: Windows Fax and Scan Service Elevation of Privilege Vulnerability Windows Fax and Scan Service Elevation of Privilege Vulnerability
nvd
CVE-2022-24454P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-24454 [HIGH] CVE-2022-24454: Windows Security Support Provider Interface Elevation of Privilege Vulnerability Windows Security Support Provider Interface Elevation of Privilege Vulnerability
nvd
CVE-2022-21981P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-21981 [HIGH] CVE-2022-21981: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-42285P3HIGHCVSS 7.8v20h22021-11-10
CVE-2021-42285 [HIGH] CWE-269 CVE-2021-42285: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2017-11927P3MEDIUMCVSS 6.5v17092017-12-12
CVE-2017-11927 [MEDIUM] CWE-200 CVE-2017-11927: Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an information vulnerability due to the way the Windows its:// protocol handler determines the zone of a request, aka "Microsoft Windows Informat
nvd