cbcvebase.

Microsoft Windows Server vulnerabilities

670 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4

Vulnerabilities

Page 18 of 34
CVE-2020-0791P3HIGHCVSS 7.8v2016v2016 (Core installation)2020-03-12
CVE-2020-0791 [HIGH] CVE-2020-0791: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898.
nvd
CVE-2018-0902P3HIGHCVSS 7.8v17092018-03-14
CVE-2018-0902 [HIGH] CVE-2018-0902: The Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) in Windows 10 Gold, 1511, 1607, The Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) in Windows 10 Gold, 1511, 1607, 1703, and 1709. Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way the kernel-mode driver validates and enforces impersonation levels, aka "Windows Security Feature Bypass Vulnerability". This CVE is
nvd
CVE-2019-1341P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-10-10
CVE-2019-1341 [HIGH] CVE-2019-1341: An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handle An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0892P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2019-05-16
CVE-2019-0892 [HIGH] CVE-2019-0892: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1316P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-10-10
CVE-2019-1316 [HIGH] CVE-2019-1316: An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly handle privileges, aka 'Microsoft Windows Setup Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0934P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+10 more2020-04-15
CVE-2020-0934 [HIGH] CVE-2020-0934: An elevation of privilege vulnerability exists when the Windows WpcDesktopMonSvc improperly manages An elevation of privilege vulnerability exists when the Windows WpcDesktopMonSvc improperly manages memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0983, CVE-2020-1009, CVE-2020-1011, CVE-2020-1015.
nvd
CVE-2019-1256P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1256 [HIGH] CVE-2019-1256: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1285.
nvd
CVE-2019-0999P3HIGHCVSS 7.8v2016v2016 (Core installation)+1 more2019-07-15
CVE-2019-0999 [HIGH] CVE-2019-0999: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1323P3HIGHCVSS 7.8v2019v2019 (Core installation)2019-10-10
CVE-2019-1323 [HIGH] CVE-2019-1323: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does n An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1336.
nvd
CVE-2019-1321P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2019-10-10
CVE-2019-1321 [HIGH] CVE-2019-1321: An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discr An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL), aka 'Microsoft Windows CloudStore Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0784P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-04-15
CVE-2020-0784 [HIGH] CVE-2020-0784: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0888.
nvd
CVE-2020-0691P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0691 [HIGH] CVE-2020-0691: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0719, CVE-2020-0720, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0725, CVE-2020-0726, CVE-2020-0731.
nvd
CVE-2020-0709P3HIGHCVSS 7.8v2016v2016 (Core installation)2020-02-11
CVE-2020-0709 [HIGH] CVE-2020-0709: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0732.
nvd
CVE-2020-0778P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+10 more2020-03-12
CVE-2020-0778 [HIGH] CVE-2020-0778: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0802, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845.
nvd
CVE-2020-0707P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-02-11
CVE-2020-0707 [HIGH] CVE-2020-0707: An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exp An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows IME Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0985P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-04-15
CVE-2020-0985 [HIGH] CVE-2020-0985: An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handl An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0996.
nvd
CVE-2020-1202P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-06-09
CVE-2020-1202 [HIGH] CVE-2020-1202: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Vi An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector fail to properly handle objects in memory, aka 'Diagnostic Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1203.
nvd
CVE-2019-1271P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1271 [HIGH] CWE-787 CVE-2019-1271: An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows Media Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0682P3HIGHCVSS 7.8vversion 1709 (Core Installation)vversion 1803 (Core Installation)+2 more2019-04-09
CVE-2019-0682 [HIGH] CWE-190 CVE-2019-0682: An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for L An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0689, CVE-2019-0692, CVE-2019-0693, CVE-2019-0694.
nvd
CVE-2019-1284P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+6 more2019-09-11
CVE-2019-1284 [HIGH] CVE-2019-1284: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
Microsoft Windows Server vulnerabilities | cvebase