Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 2 of 36
CVE-2019-0797P2HIGHCVSS 7.8KEVv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+6 more2019-04-09
CVE-2019-0797 [HIGH] CVE-2019-0797: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.
nvd
CVE-2019-1214P2HIGHCVSS 7.8KEVv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1214 [HIGH] CWE-119 CVE-2019-1214: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0703P2MEDIUMCVSS 6.5KEVv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+5 more2019-04-09
CVE-2019-0703 [MEDIUM] CVE-2019-0703: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.
nvd
CVE-2022-21907P1CRITICALCVSS 9.8ExploitedPoCv20h2v20222022-01-11
CVE-2022-21907 [CRITICAL] CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability
HTTP Protocol Stack Remote Code Execution Vulnerability
nvd
CVE-2020-0609P1CRITICALCVSS 9.8ExploitedPoCRansomwarev2019v2016+2 more2020-01-14
CVE-2020-0609 [CRITICAL] CVE-2020-0609: A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.
nvd
CVE-2020-0624P1HIGHCVSS 7.8ExploitedPoCRansomwarevversion 1803 (Core Installation)v2019+15 more2020-01-14
CVE-2020-0624 [HIGH] CVE-2020-0624: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.
nvd
CVE-2020-1048P2HIGHCVSS 7.8ExploitedPoCvversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1048 [HIGH] CWE-669 CVE-2020-1048: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1070.
nvd
CVE-2019-0623P2HIGHCVSS 7.8ExploitedPoCv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+14 more2019-03-05
CVE-2019-0623 [HIGH] CVE-2019-0623: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0630P1HIGHCVSS 8.8Exploitedv2012v2012 (Core installation)+8 more2019-03-05
CVE-2019-0630 [HIGH] CWE-19 CVE-2019-0630: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0633.
nvd
CVE-2021-43207P1HIGHCVSS 7.8ExploitedRansomwarev20h2v20222021-12-15
CVE-2021-43207 [HIGH] CVE-2021-43207: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-0611P1HIGHCVSS 7.5ExploitedRansomwarevversion 1803 (Core Installation)v2019+10 more2020-01-14
CVE-2020-0611 [HIGH] CVE-2020-0611: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2019-1108P1MEDIUMCVSS 6.5ExploitedRansomwarev2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-07-15
CVE-2019-1108 [MEDIUM] CWE-200 CVE-2019-1108: An information disclosure vulnerability exists when the Windows RDP client improperly discloses the
An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.
nvd
CVE-2020-1375P2HIGHCVSS 7.8Exploitedv2019v2019 (Core installation)2020-07-14
CVE-2020-1375 [HIGH] CVE-2020-1375: An elevation of privilege vulnerability exists when Windows improperly handles COM object creation,
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0784P2HIGHCVSS 7.5Exploitedv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 12019-04-09
CVE-2019-0784 [HIGH] CWE-787 CVE-2019-0784: A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles
A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles objects in memory, aka 'Windows ActiveX Remote Code Execution Vulnerability'.
nvd
CVE-2022-21874P2CRITICALCVSS 9.8Exploitedv20h2v20222022-01-11
CVE-2022-21874 [CRITICAL] CVE-2022-21874: Windows Security Center API Remote Code Execution Vulnerability
Windows Security Center API Remote Code Execution Vulnerability
nvd
CVE-2022-21898P3CRITICALCVSS 9.8Exploitedv20h2v20222022-01-11
CVE-2022-21898 [CRITICAL] CVE-2022-21898: DirectX Graphics Kernel Remote Code Execution Vulnerability
DirectX Graphics Kernel Remote Code Execution Vulnerability
nvd
CVE-2019-1117P2HIGHCVSS 8.8PoCvversion 1803 (Core Installation)v2019+1 more2019-07-15
CVE-2019-1117 [HIGH] CVE-2019-1117: A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory,
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
nvd
CVE-2022-26937P2CRITICALCVSS 9.8v20h22022-05-10
CVE-2022-26937 [CRITICAL] CVE-2022-26937: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2019-0626P2CRITICALCVSS 9.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-03-05
CVE-2019-0626 [CRITICAL] CWE-787 CVE-2019-0626: A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends s
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
nvd
CVE-2022-21972P2HIGHCVSS 8.1v20h22022-05-10
CVE-2022-21972 [HIGH] CVE-2022-21972: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd