Microsoft Windows Server vulnerabilities
670 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4
Vulnerabilities
Page 14 of 34
CVE-2020-0844P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+8 more2020-03-12
CVE-2020-0844 [HIGH] CVE-2020-0844: An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service
An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1431P3HIGHCVSS 7.8v2019v2019 (Core installation)2020-07-14
CVE-2020-1431 [HIGH] CWE-269 CVE-2020-1431: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correc
nvd
CVE-2022-21873P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21873 [HIGH] CVE-2022-21873: Tile Data Repository Elevation of Privilege Vulnerability
Tile Data Repository Elevation of Privilege Vulnerability
nvd
CVE-2022-23293P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23293 [HIGH] CVE-2022-23293: Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21861P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21861 [HIGH] CVE-2022-21861: Task Flow Data Engine Elevation of Privilege Vulnerability
Task Flow Data Engine Elevation of Privilege Vulnerability
nvd
CVE-2021-40443P3HIGHCVSS 7.8v20h22021-10-13
CVE-2021-40443 [HIGH] CWE-269 CVE-2021-40443: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-24459P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-24459 [HIGH] CVE-2022-24459: Windows Fax and Scan Service Elevation of Privilege Vulnerability
Windows Fax and Scan Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21834P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21834 [HIGH] CVE-2022-21834: Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability
Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21981P3HIGHCVSS 7.8v20h2v20222022-02-09
CVE-2022-21981 [HIGH] CVE-2022-21981: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-42285P3HIGHCVSS 7.8v20h22021-11-10
CVE-2021-42285 [HIGH] CWE-269 CVE-2021-42285: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2017-11927P3MEDIUMCVSS 6.5v17092017-12-12
CVE-2017-11927 [MEDIUM] CWE-200 CVE-2017-11927: Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an information vulnerability due to the way the Windows its:// protocol handler determines the zone of a request, aka "Microsoft Windows Informat
nvd
CVE-2020-0660P3HIGHCVSS 7.5vversion 1803 (Core Installation)v2019+7 more2020-02-11
CVE-2020-0660 [HIGH] CVE-2020-0660: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2020-1287P3HIGHCVSS 7.8v2019 (Core installation)v2019+3 more2020-06-09
CVE-2020-1287 [HIGH] CVE-2020-1287: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj
An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294.
nvd
CVE-2020-1291P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1291 [HIGH] CVE-2020-1291: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1314P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1314 [HIGH] CVE-2020-1314: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messages sent from TSF clients, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1280P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-06-09
CVE-2020-1280 [HIGH] CVE-2020-1280: An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles
An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles objects in memory, aka 'Windows Bluetooth Service Elevation of Privilege Vulnerability'.
nvd
CVE-2021-43236P3HIGHCVSS 7.5v20h2v20222021-12-15
CVE-2021-43236 [HIGH] CVE-2021-43236: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2021-43222P3HIGHCVSS 7.5v20h2v20222021-12-15
CVE-2021-43222 [HIGH] CVE-2021-43222: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2019-0627P3HIGHCVSS 7.8v2016v2016 (Core installation)+4 more2019-03-05
CVE-2019-0627 [HIGH] CVE-2019-0627: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass De
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632.
nvd
CVE-2020-1424P3HIGHCVSS 7.8v2019v2019 (Core installation)2020-07-14
CVE-2020-1424 [HIGH] CVE-2020-1424: An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handl
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'.
nvd