cbcvebase.

Microsoft Windows Server vulnerabilities

670 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4

Vulnerabilities

Page 15 of 34
CVE-2020-1207P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-06-09
CVE-2020-1207 [HIGH] CWE-416 CVE-2020-1207: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1247, CVE-2020-1251, CVE-2020-1253, CVE-2020-1310.
nvd
CVE-2020-0634P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-01-14
CVE-2020-0634 [HIGH] CWE-416 CVE-2020-0634: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
nvd
CVE-2018-8554P3HIGHCVSS 7.8v18032018-11-14
CVE-2018-8554 [HIGH] CVE-2018-8554: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019. This CVE ID is unique from CVE-2018-8485, CVE-2018-8561.
nvd
CVE-2019-1267P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+8 more2019-09-11
CVE-2019-1267 [HIGH] CWE-59 CVE-2019-1267: An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configur An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks, aka 'Microsoft Compatibility Appraiser Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1477P3HIGHCVSS 7.8v2019v2019 (Core installation)2019-12-10
CVE-2019-1477 [HIGH] CVE-2019-1477: An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers, aka 'Windows Printer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0861P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+5 more2020-03-12
CVE-2020-0861 [HIGH] CVE-2020-0861: An information disclosure vulnerability exists when the Windows Network Driver Interface Specificati An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Network Driver Interface Specification (NDIS) Information Disclosure Vulnerability'.
nvd
CVE-2019-1268P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1268 [HIGH] CVE-2019-1268: An elevation of privilege exists when Winlogon does not properly handle file path information, aka ' An elevation of privilege exists when Winlogon does not properly handle file path information, aka 'Winlogon Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1082P3HIGHCVSS 7.8v18032020-05-21
CVE-2020-1082 [HIGH] CWE-22 CVE-2020-1082: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. To explo
nvd
CVE-2019-1319P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-10-10
CVE-2019-1319 [HIGH] CVE-2019-1319: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0776P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-03-12
CVE-2020-0776 [HIGH] CVE-2020-0776: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly ha An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0858.
nvd
CVE-2020-0769P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0769 [HIGH] CVE-2020-0769: An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memor An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0771.
nvd
CVE-2020-1336P3HIGHCVSS 7.8v2019v2019 (Core installation)+2 more2020-07-14
CVE-2020-1336 [HIGH] CVE-2020-1336: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerabili
nvd
CVE-2020-0757P3HIGHCVSS 7.8v2019 (Core installation)v20192020-02-11
CVE-2020-0757 [HIGH] CVE-2020-0757: An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell r An elevation of privilege vulnerability exists when Windows improperly handles Secure Socket Shell remote commands, aka 'Windows SSH Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0678P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0678 [HIGH] CVE-2020-0678: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handl An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'.
nvd
CVE-2022-21908P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21908 [HIGH] CVE-2022-21908: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1429P3HIGHCVSS 7.8v2019v2019 (Core installation)+2 more2020-07-14
CVE-2020-1429 [HIGH] CVE-2020-1429: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handl An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1197P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-06-09
CVE-2020-1197 [HIGH] CVE-2020-1197: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handl An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0819P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-03-12
CVE-2020-0819 [HIGH] CVE-2020-0819: An elevation of privilege vulnerability exists when the Windows Device Setup Manager improperly hand An elevation of privilege vulnerability exists when the Windows Device Setup Manager improperly handles file operations, aka 'Windows Device Setup Manager Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0834P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+5 more2020-03-12
CVE-2020-0834 [HIGH] CVE-2020-0834: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1014P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-1014 [HIGH] CWE-269 CVE-2020-1014: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does n An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'.
nvd
Microsoft Windows Server vulnerabilities | cvebase