cbcvebase.

Microsoft Windows Server vulnerabilities

705 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4

Vulnerabilities

Page 22 of 36
CVE-2020-1279P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-06-09
CVE-2020-1279 [HIGH] CVE-2020-1279: An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotli An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotlight images from a secure location, aka 'Windows Lockscreen Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1087P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1087 [HIGH] CVE-2020-1087: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1114.
nvd
CVE-2020-1124P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-05-21
CVE-2020-1124 [HIGH] CVE-2020-1124: An elevation of privilege vulnerability exists when the Windows State Repository Service improperly An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows State Repository Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1131, CVE-2020-1134, CVE-2020-1144, CVE-2020-1184, CVE-2020-1185, CVE-2020-1186, CVE-2020-1187, CVE-2020-1188, CVE-2020-1189
nvd
CVE-2022-21884P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21884 [HIGH] CVE-2022-21884: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2021-43239P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43239 [HIGH] CVE-2021-43239: Windows Recovery Environment Agent Elevation of Privilege Vulnerability Windows Recovery Environment Agent Elevation of Privilege Vulnerability
nvd
CVE-2021-43248P3HIGHCVSS 7.8v20h2v20222021-12-15
CVE-2021-43248 [HIGH] CVE-2021-43248: Windows Digital Media Receiver Elevation of Privilege Vulnerability Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2021-42286P3HIGHCVSS 7.8v20h22021-11-10
CVE-2021-42286 [HIGH] CWE-269 CVE-2021-42286: Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerabi Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
nvd
CVE-2021-40460P3MEDIUMCVSS 6.5v20h22021-10-13
CVE-2021-40460 [MEDIUM] CVE-2021-40460: Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
nvd
CVE-2019-0811P3HIGHCVSS 7.5v2012 R2v2012 R2 (Core installation)+5 more2019-07-15
CVE-2019-0811 [HIGH] CWE-19 CVE-2019-0811: A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Windows DNS Server Denial of Service Vulnerability'.
nvd
CVE-2019-0758P3MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-05-16
CVE-2019-0758 [MEDIUM] CVE-2019-0758: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961.
nvd
CVE-2022-23286P3HIGHCVSS 7.0v20h2v20222022-03-09
CVE-2022-23286 [HIGH] CVE-2022-23286: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-26932P3HIGHCVSS 8.2v20h22022-05-10
CVE-2022-26932 [HIGH] CVE-2022-26932: Storage Spaces Direct Elevation of Privilege Vulnerability Storage Spaces Direct Elevation of Privilege Vulnerability
nvd
CVE-2018-0884P3HIGHCVSS 7.8v17092018-03-14
CVE-2018-0884 [HIGH] CVE-2018-0884: Windows Scripting Host (WSH) in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Scripting Host (WSH) in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to how objects are handled in memory, aka "Windows Security Feature Bypass Vulnerability". This CVE is unique from CVE-2018-0902.
nvd
CVE-2019-0696P3HIGHCVSS 7.8v2016v2016 (Core installation)+4 more2019-04-09
CVE-2019-0696 [HIGH] CVE-2019-0696: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0635P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-01-14
CVE-2020-0635 [HIGH] CWE-269 CVE-2020-0635: An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly h An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644.
nvd
CVE-2019-1320P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2019-10-10
CVE-2019-1320 [HIGH] CVE-2019-1320: An elevation of privilege vulnerability exists when Windows improperly handles authentication reques An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1322, CVE-2019-1340.
nvd
CVE-2019-1090P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2019-07-15
CVE-2019-1090 [HIGH] CVE-2019-1090: An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in m An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory, aka 'Windows dnsrlvr.dll Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1067P3HIGHCVSS 7.8v2016v2016 (Core installation)+3 more2019-07-15
CVE-2019-1067 [HIGH] CVE-2019-1067: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0788P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0788 [HIGH] CVE-2020-0788: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0877, CVE-2020-0887.
nvd
CVE-2020-0777P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+5 more2020-03-12
CVE-2020-0777 [HIGH] CVE-2020-0777: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0797, CVE-2020-0800, CVE-2020-0864, CVE-2020-0865, CVE-2020-0866, CVE-2020-0897.
nvd
Microsoft Windows Server vulnerabilities | cvebase