Microsoft Windows Server vulnerabilities
670 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4
Vulnerabilities
Page 17 of 34
CVE-2022-21875P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21875 [HIGH] CVE-2022-21875: Windows Storage Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2022-21872P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21872 [HIGH] CVE-2022-21872: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2022-21870P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21870 [HIGH] CVE-2022-21870: Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
nvd
CVE-2022-21835P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21835 [HIGH] CVE-2022-21835: Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
nvd
CVE-2022-23296P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23296 [HIGH] CWE-269 CVE-2022-23296: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2022-21902P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21902 [HIGH] CWE-269 CVE-2022-21902: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-23291P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23291 [HIGH] CVE-2022-23291: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-21833P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21833 [HIGH] CVE-2022-21833: Virtual Machine IDE Drive Elevation of Privilege Vulnerability
Virtual Machine IDE Drive Elevation of Privilege Vulnerability
nvd
CVE-2022-24454P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-24454 [HIGH] CVE-2022-24454: Windows Security Support Provider Interface Elevation of Privilege Vulnerability
Windows Security Support Provider Interface Elevation of Privilege Vulnerability
nvd
CVE-2022-23290P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23290 [HIGH] CVE-2022-23290: Windows Inking COM Elevation of Privilege Vulnerability
Windows Inking COM Elevation of Privilege Vulnerability
nvd
CVE-2019-1235P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1235 [HIGH] CWE-346 CVE-2019-1235: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2022-21910P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21910 [HIGH] CVE-2022-21910: Microsoft Cluster Port Driver Elevation of Privilege Vulnerability
Microsoft Cluster Port Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-43240P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43240 [HIGH] CVE-2021-43240: NTFS Set Short Name Elevation of Privilege Vulnerability
NTFS Set Short Name Elevation of Privilege Vulnerability
nvd
CVE-2021-42286P3HIGHCVSS 7.8v20h22021-11-10
CVE-2021-42286 [HIGH] CWE-269 CVE-2021-42286: Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerabi
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
nvd
CVE-2020-1217P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-06-09
CVE-2020-1217 [HIGH] CVE-2020-1217: An information disclosure vulnerability exists when the Windows Runtime improperly handles objects i
An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Information Disclosure Vulnerability'.
nvd
CVE-2020-1231P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-06-09
CVE-2020-1231 [HIGH] CVE-2020-1231: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1304, CVE-2020-1306, CVE-2020-1334.
nvd
CVE-2022-29142P3HIGHCVSS 7.0v20h22022-05-10
CVE-2022-29142 [HIGH] CVE-2022-29142: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-0838P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+14 more2019-04-09
CVE-2019-0838 [HIGH] CVE-2019-0838: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses cred
An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
nvd
CVE-2020-0637P3MEDIUMCVSS 6.5v2019v2019 (Core installation)+8 more2020-01-14
CVE-2020-0637 [MEDIUM] CVE-2020-0637: An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles cre
An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.
nvd
CVE-2019-1393P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd