cbcvebase.

Microsoft Windows Server vulnerabilities

705 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4

Vulnerabilities

Page 18 of 36
CVE-2022-23291P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23291 [HIGH] CVE-2022-23291: Windows DWM Core Library Elevation of Privilege Vulnerability Windows DWM Core Library Elevation of Privilege Vulnerability
nvd
CVE-2019-1235P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1235 [HIGH] CWE-346 CVE-2019-1235: An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
nvd
CVE-2022-23290P3HIGHCVSS 7.8v20h2v20222022-03-09
CVE-2022-23290 [HIGH] CVE-2022-23290: Windows Inking COM Elevation of Privilege Vulnerability Windows Inking COM Elevation of Privilege Vulnerability
nvd
CVE-2022-21910P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21910 [HIGH] CVE-2022-21910: Microsoft Cluster Port Driver Elevation of Privilege Vulnerability Microsoft Cluster Port Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-43240P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43240 [HIGH] CVE-2021-43240: NTFS Set Short Name Elevation of Privilege Vulnerability NTFS Set Short Name Elevation of Privilege Vulnerability
nvd
CVE-2020-1217P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-06-09
CVE-2020-1217 [HIGH] CVE-2020-1217: An information disclosure vulnerability exists when the Windows Runtime improperly handles objects i An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Information Disclosure Vulnerability'.
nvd
CVE-2020-0660P3HIGHCVSS 7.5vversion 1803 (Core Installation)v2019+7 more2020-02-11
CVE-2020-0660 [HIGH] CVE-2020-0660: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2020-1231P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-06-09
CVE-2020-1231 [HIGH] CVE-2020-1231: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE-2020-1282, CVE-2020-1304, CVE-2020-1306, CVE-2020-1334.
nvd
CVE-2022-29142P3HIGHCVSS 7.0v20h22022-05-10
CVE-2022-29142 [HIGH] CVE-2022-29142: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-1287P3HIGHCVSS 7.8v2019 (Core installation)v2019+3 more2020-06-09
CVE-2020-1287 [HIGH] CVE-2020-1287: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294.
nvd
CVE-2020-1291P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1291 [HIGH] CVE-2020-1291: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1280P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-06-09
CVE-2020-1280 [HIGH] CVE-2020-1280: An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles objects in memory, aka 'Windows Bluetooth Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0838P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+14 more2019-04-09
CVE-2019-0838 [HIGH] CVE-2019-0838: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses cred An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
nvd
CVE-2020-0637P3MEDIUMCVSS 6.5v2019v2019 (Core installation)+8 more2020-01-14
CVE-2020-0637 [MEDIUM] CVE-2020-0637: An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles cre An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.
nvd
CVE-2019-1393P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2018-0902P3HIGHCVSS 7.8v17092018-03-14
CVE-2018-0902 [HIGH] CVE-2018-0902: The Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) in Windows 10 Gold, 1511, 1607, The Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) in Windows 10 Gold, 1511, 1607, 1703, and 1709. Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way the kernel-mode driver validates and enforces impersonation levels, aka "Windows Security Feature Bypass Vulnerability". This CVE is
nvd
CVE-2020-0791P3HIGHCVSS 7.8v2016v2016 (Core installation)2020-03-12
CVE-2020-0791 [HIGH] CVE-2020-0791: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898.
nvd
CVE-2019-0892P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2019-05-16
CVE-2019-0892 [HIGH] CVE-2019-0892: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1341P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-10-10
CVE-2019-1341 [HIGH] CVE-2019-1341: An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handle An elevation of privilege vulnerability exists when umpo.dll of the Power Service, improperly handles a Registry Restore Key function, aka 'Windows Power Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1256P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1256 [HIGH] CVE-2019-1256: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1285.
nvd
Microsoft Windows Server vulnerabilities | cvebase