Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 22 of 36
CVE-2020-1279P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-06-09
CVE-2020-1279 [HIGH] CVE-2020-1279: An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotli
An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotlight images from a secure location, aka 'Windows Lockscreen Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1087P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1087 [HIGH] CVE-2020-1087: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1114.
nvd
CVE-2020-1124P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-05-21
CVE-2020-1124 [HIGH] CVE-2020-1124: An elevation of privilege vulnerability exists when the Windows State Repository Service improperly
An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1131, CVE-2020-1134, CVE-2020-1144, CVE-2020-1184, CVE-2020-1185, CVE-2020-1186, CVE-2020-1187, CVE-2020-1188, CVE-2020-1189
nvd
CVE-2022-21884P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21884 [HIGH] CVE-2022-21884: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2021-43239P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43239 [HIGH] CVE-2021-43239: Windows Recovery Environment Agent Elevation of Privilege Vulnerability
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
nvd
CVE-2021-43248P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43248 [HIGH] CVE-2021-43248: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2021-42286P3HIGHCVSS 7.8v20h22021-11-10
CVE-2021-42286 [HIGH] CWE-269 CVE-2021-42286: Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerabi
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
nvd
CVE-2021-40460P3MEDIUMCVSS 6.5v20h22021-10-13
CVE-2021-40460 [MEDIUM] CVE-2021-40460: Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
nvd
CVE-2019-0811P3HIGHCVSS 7.5v2012 R2v2012 R2 (Core installation)+5 more2019-07-15
CVE-2019-0811 [HIGH] CWE-19 CVE-2019-0811: A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS
A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Windows DNS Server Denial of Service Vulnerability'.
nvd
CVE-2019-0758P3MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-05-16
CVE-2019-0758 [MEDIUM] CVE-2019-0758: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961.
nvd
CVE-2022-23286P3HIGHCVSS 7.0v20h2v20222022-03-09
CVE-2022-23286 [HIGH] CVE-2022-23286: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-26932P3HIGHCVSS 8.2v20h22022-05-10
CVE-2022-26932 [HIGH] CVE-2022-26932: Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability
nvd
CVE-2018-0884P3HIGHCVSS 7.8v17092018-03-14
CVE-2018-0884 [HIGH] CVE-2018-0884: Windows Scripting Host (WSH) in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and
Windows Scripting Host (WSH) in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to how objects are handled in memory, aka "Windows Security Feature Bypass Vulnerability". This CVE is unique from CVE-2018-0902.
nvd
CVE-2019-0696P3HIGHCVSS 7.8v2016v2016 (Core installation)+4 more2019-04-09
CVE-2019-0696 [HIGH] CVE-2019-0696: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0635P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-01-14
CVE-2020-0635 [HIGH] CWE-269 CVE-2020-0635: An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly h
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644.
nvd
CVE-2019-1320P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2019-10-10
CVE-2019-1320 [HIGH] CVE-2019-1320: An elevation of privilege vulnerability exists when Windows improperly handles authentication reques
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1322, CVE-2019-1340.
nvd
CVE-2019-1090P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2019-07-15
CVE-2019-1090 [HIGH] CVE-2019-1090: An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in m
An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory, aka 'Windows dnsrlvr.dll Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1067P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-07-15
CVE-2019-1067 [HIGH] CVE-2019-1067: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0788P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0788 [HIGH] CVE-2020-0788: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0877, CVE-2020-0887.
nvd
CVE-2020-0777P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+5 more2020-03-12
CVE-2020-0777 [HIGH] CVE-2020-0777: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl
An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0797, CVE-2020-0800, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897.
nvd