cbcvebase.

Microsoft Windows Server vulnerabilities

670 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4

Vulnerabilities

Page 16 of 34
CVE-2020-1402P3HIGHCVSS 7.8v2019v2019 (Core installation)+8 more2020-07-14
CVE-2020-1402 [HIGH] CVE-2020-1402: An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0799P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-03-12
CVE-2020-0799 [HIGH] CWE-269 CVE-2020-0799: An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0659P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-02-11
CVE-2020-0659 [HIGH] CVE-2020-0659: An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly hand An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0747.
nvd
CVE-2019-1415P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-11-12
CVE-2019-1415 [HIGH] CVE-2019-1415: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1380P3HIGHCVSS 7.8v2012v2012 (Core installation)+7 more2019-11-12
CVE-2019-1380 [HIGH] CWE-367 CVE-2019-1380: A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka ' A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1354P3HIGHCVSS 7.8v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1354 [HIGH] CVE-2020-1354: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1430.
nvd
CVE-2020-0793P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-03-12
CVE-2020-0793 [HIGH] CVE-2020-0793: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service i An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0701P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-02-11
CVE-2020-0701 [HIGH] CVE-2020-0701: An elevation of privilege vulnerability exists in the way that the Windows Client License Service (C An elevation of privilege vulnerability exists in the way that the Windows Client License Service (ClipSVC) handles objects in memory, aka 'Windows Client License Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1347P3HIGHCVSS 7.8v2019v2019 (Core installation)2020-07-14
CVE-2020-1347 [HIGH] CVE-2020-1347: An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle f An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations, aka 'Windows Storage Services Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1379P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-11-12
CVE-2019-1379 [HIGH] CVE-2019-1379: An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly hand An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1383, CVE-2019-1417.
nvd
CVE-2020-0808P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-03-12
CVE-2020-0808 [HIGH] CWE-20 CVE-2020-0808: An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain An elevation of privilege vulnerability exists in the way the Provisioning Runtime validates certain file operations, aka 'Provisioning Runtime Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0620P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-01-14
CVE-2020-0620 [HIGH] CVE-2020-0620: An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly hand An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1363P3HIGHCVSS 7.8v2019v2019 (Core installation)2020-07-14
CVE-2020-1363 [HIGH] CVE-2020-1363: An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles m An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1352P3HIGHCVSS 7.8v2019v2019 (Core installation)+2 more2020-07-14
CVE-2020-1352 [HIGH] CVE-2020-1352: An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles m An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1356P3HIGHCVSS 7.8v2019v2019 (Core installation)+6 more2020-07-14
CVE-2020-1356 [HIGH] CVE-2020-1356: An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly hand An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations, aka 'Windows iSCSI Target Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1372P3HIGHCVSS 7.8v20192020-07-14
CVE-2020-1372 [HIGH] CVE-2020-1372: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnosti An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1405.
nvd
CVE-2022-29132P3HIGHCVSS 7.8v20h22022-05-10
CVE-2022-29132 [HIGH] CVE-2022-29132: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-21852P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21852 [HIGH] CWE-119 CVE-2022-21852: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-21858P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21858 [HIGH] CVE-2022-21858: Windows Bind Filter Driver Elevation of Privilege Vulnerability Windows Bind Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21871P3HIGHCVSS 7.8v20222022-01-11
CVE-2022-21871 [HIGH] CVE-2022-21871: Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server vulnerabilities | cvebase