Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 17 of 36
CVE-2019-1380P3HIGHCVSS 7.8v2012v2012 (Core installation)+7 more2019-11-12
CVE-2019-1380 [HIGH] CWE-367 CVE-2019-1380: A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka '
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0620P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-01-14
CVE-2020-0620 [HIGH] CVE-2020-0620: An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly hand
An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1363P3HIGHCVSS 7.8v2019v2019 (Core installation)2020-07-14
CVE-2020-1363 [HIGH] CVE-2020-1363: An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles m
An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1352P3HIGHCVSS 7.8v2019v2019 (Core installation)+2 more2020-07-14
CVE-2020-1352 [HIGH] CVE-2020-1352: An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles m
An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1078P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1078 [HIGH] CVE-2020-1078: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1379P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-11-12
CVE-2019-1379 [HIGH] CVE-2019-1379: An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly hand
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1383, CVE-2019-1417.
nvd
CVE-2020-1356P3HIGHCVSS 7.8v2019v2019 (Core installation)+6 more2020-07-14
CVE-2020-1356 [HIGH] CVE-2020-1356: An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly hand
An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations, aka 'Windows iSCSI Target Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1372P3HIGHCVSS 7.8v20192020-07-14
CVE-2020-1372 [HIGH] CVE-2020-1372: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnosti
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1405.
nvd
CVE-2020-1368P3HIGHCVSS 7.8v2019v2019 (Core installation)+6 more2020-07-14
CVE-2020-1368 [HIGH] CVE-2020-1368: An elevation of privilege vulnerability exists in the way that the Credential Enrollment Manager ser
An elevation of privilege vulnerability exists in the way that the Credential Enrollment Manager service handles objects in memory, aka 'Windows Credential Enrollment Manager Service Elevation of Privilege Vulnerability'.
nvd
CVE-2022-21852P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21852 [HIGH] CWE-119 CVE-2022-21852: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-21858P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21858 [HIGH] CVE-2022-21858: Windows Bind Filter Driver Elevation of Privilege Vulnerability
Windows Bind Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21871P3HIGHCVSS 7.8v20222022-01-11
CVE-2022-21871 [HIGH] CVE-2022-21871: Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
nvd
CVE-2022-21875P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21875 [HIGH] CVE-2022-21875: Windows Storage Elevation of Privilege Vulnerability
Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2022-21872P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21872 [HIGH] CVE-2022-21872: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2022-21870P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21870 [HIGH] CVE-2022-21870: Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
nvd
CVE-2022-21835P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21835 [HIGH] CVE-2022-21835: Microsoft Cryptographic Services Elevation of Privilege Vulnerability
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
nvd
CVE-2022-29132P3HIGHCVSS 7.8v20h22022-05-10
CVE-2022-29132 [HIGH] CVE-2022-29132: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-21902P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21902 [HIGH] CWE-269 CVE-2022-21902: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2022-23296P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23296 [HIGH] CWE-269 CVE-2022-23296: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2022-21833P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21833 [HIGH] CVE-2022-21833: Virtual Machine IDE Drive Elevation of Privilege Vulnerability
Virtual Machine IDE Drive Elevation of Privilege Vulnerability
nvd