cbcvebase.

Microsoft Windows Server vulnerabilities

670 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4

Vulnerabilities

Page 17 of 34
CVE-2022-21875P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21875 [HIGH] CVE-2022-21875: Windows Storage Elevation of Privilege Vulnerability Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2022-21872P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21872 [HIGH] CVE-2022-21872: Windows Event Tracing Elevation of Privilege Vulnerability Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2022-21870P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21870 [HIGH] CVE-2022-21870: Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
nvd
CVE-2022-21835P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21835 [HIGH] CVE-2022-21835: Microsoft Cryptographic Services Elevation of Privilege Vulnerability Microsoft Cryptographic Services Elevation of Privilege Vulnerability
nvd
CVE-2022-23296P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23296 [HIGH] CWE-269 CVE-2022-23296: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2022-21902P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21902 [HIGH] CWE-269 CVE-2022-21902: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-23291P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23291 [HIGH] CVE-2022-23291: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-21833P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21833 [HIGH] CVE-2022-21833: Virtual Machine IDE Drive Elevation of Privilege Vulnerability Virtual Machine IDE Drive Elevation of Privilege Vulnerability
nvd
CVE-2022-24454P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-24454 [HIGH] CVE-2022-24454: Windows Security Support Provider Interface Elevation of Privilege Vulnerability Windows Security Support Provider Interface Elevation of Privilege Vulnerability
nvd
CVE-2022-23290P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23290 [HIGH] CVE-2022-23290: Windows Inking COM Elevation of Privilege Vulnerability Windows Inking COM Elevation of Privilege Vulnerability
nvd
CVE-2019-1235P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1235 [HIGH] CWE-346 CVE-2019-1235: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2022-21910P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21910 [HIGH] CVE-2022-21910: Microsoft Cluster Port Driver Elevation of Privilege Vulnerability Microsoft Cluster Port Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-43240P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43240 [HIGH] CVE-2021-43240: NTFS Set Short Name Elevation of Privilege Vulnerability NTFS Set Short Name Elevation of Privilege Vulnerability
nvd
CVE-2021-42286P3HIGHCVSS 7.8v20h22021-11-10
CVE-2021-42286 [HIGH] CWE-269 CVE-2021-42286: Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerabi Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
nvd
CVE-2020-1217P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-06-09
CVE-2020-1217 [HIGH] CVE-2020-1217: An information disclosure vulnerability exists when the Windows Runtime improperly handles objects i An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Information Disclosure Vulnerability'.
nvd
CVE-2020-1231P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-06-09
CVE-2020-1231 [HIGH] CVE-2020-1231: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1304, CVE-2020-1306, CVE-2020-1334.
nvd
CVE-2022-29142P3HIGHCVSS 7.0v20h22022-05-10
CVE-2022-29142 [HIGH] CVE-2022-29142: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-0838P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+14 more2019-04-09
CVE-2019-0838 [HIGH] CVE-2019-0838: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses cred An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
nvd
CVE-2020-0637P3MEDIUMCVSS 6.5v2019v2019 (Core installation)+8 more2020-01-14
CVE-2020-0637 [MEDIUM] CVE-2020-0637: An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles cre An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.
nvd
CVE-2019-1393P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
Microsoft Windows Server vulnerabilities | cvebase