Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 19 of 36
CVE-2019-1316P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-10-10
CVE-2019-1316 [HIGH] CVE-2019-1316: An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly
An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly handle privileges, aka 'Microsoft Windows Setup Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0999P3HIGHCVSS 7.8v2016v2016 (Core installation)+1 more2019-07-15
CVE-2019-0999 [HIGH] CVE-2019-0999: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0934P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+10 more2020-04-15
CVE-2020-0934 [HIGH] CVE-2020-0934: An elevation of privilege vulnerability exists when the Windows WpcDesktopMonSvc improperly manages
An elevation of privilege vulnerability exists when the Windows WpcDesktopMonSvc improperly manages memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0983, CVE-2020-1009, CVE-2020-1011, CVE-2020-1015.
nvd
CVE-2020-0691P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0691 [HIGH] CVE-2020-0691: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0719, CVE-2020-0720, CVE-2020-0721, CVE-2020-0722, CVE-2020-0723, CVE-2020-0724, CVE-2020-0725, CVE-2020-0726, CVE-2020-0731.
nvd
CVE-2020-0709P3HIGHCVSS 7.8v2016v2016 (Core installation)2020-02-11
CVE-2020-0709 [HIGH] CVE-2020-0709: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0732.
nvd
CVE-2020-1344P3HIGHCVSS 7.8v2019v2019 (Core installation)+2 more2020-07-14
CVE-2020-1344 [HIGH] CVE-2020-1344: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj
An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1362, CVE-2020-1369.
nvd
CVE-2020-0778P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+10 more2020-03-12
CVE-2020-0778 [HIGH] CVE-2020-0778: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0802, CVE-2020-0803, CVE-2020-0804, CVE-2020-0845.
nvd
CVE-2020-0707P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-02-11
CVE-2020-0707 [HIGH] CVE-2020-0707: An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exp
An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows IME Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0784P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-04-15
CVE-2020-0784 [HIGH] CVE-2020-0784: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0888.
nvd
CVE-2019-1271P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1271 [HIGH] CWE-787 CVE-2019-1271: An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows
An elevation of privilege exists in hdAudio.sys which may lead to an out of band write, aka 'Windows Media Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0682P3HIGHCVSS 7.8vversion 1709 (Core Installation)vversion 1803 (Core Installation)+2 more2019-04-09
CVE-2019-0682 [HIGH] CWE-190 CVE-2019-0682: An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for L
An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0689, CVE-2019-0692, CVE-2019-0693, CVE-2019-0694.
nvd
CVE-2019-1284P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+6 more2019-09-11
CVE-2019-1284 [HIGH] CVE-2019-1284: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0985P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-04-15
CVE-2020-0985 [HIGH] CVE-2020-0985: An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handl
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0996.
nvd
CVE-2020-1082P3HIGHCVSS 7.8v18032020-05-21
CVE-2020-1082 [HIGH] CVE-2020-1082: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1021, CVE-2020-1088.
nvd
CVE-2020-1393P3HIGHCVSS 7.8v2019v2019 (Core installation)2020-07-14
CVE-2020-1393 [HIGH] CVE-2020-1393: An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector S
An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1418.
nvd
CVE-2020-0685P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-02-11
CVE-2020-0685 [HIGH] CVE-2020-0685: An elevation of privilege vulnerability exists when Windows improperly handles COM object creation,
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1323P3HIGHCVSS 7.8v2019v2019 (Core installation)2019-10-10
CVE-2019-1323 [HIGH] CVE-2019-1323: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does n
An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1336.
nvd
CVE-2019-1321P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2019-10-10
CVE-2019-1321 [HIGH] CVE-2019-1321: An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discr
An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL), aka 'Microsoft Windows CloudStore Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0956P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0956 [HIGH] CVE-2020-0956: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0957, CVE-2020-0958.
nvd
CVE-2020-1094P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+8 more2020-04-15
CVE-2020-1094 [HIGH] CVE-2020-1094: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl
An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'.
nvd