Microsoft Windows Server vulnerabilities
670 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4
Vulnerabilities
Page 22 of 34
CVE-2020-0666P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0666 [HIGH] CVE-2020-0666: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0667, CVE-2020-0735, CVE-2020-0752.
nvd
CVE-2020-0613P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-01-14
CVE-2020-0613 [HIGH] CVE-2020-0613: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CV
nvd
CVE-2020-1388P3HIGHCVSS 7.8v2019v2019 (Core installation)+2 more2020-07-14
CVE-2020-1388 [HIGH] CVE-2020-1388: An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in mem
An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1392, CVE-2020-1394, CVE-2020-1395.
nvd
CVE-2020-0737P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-02-11
CVE-2020-0737 [HIGH] CVE-2020-0737: An elevation of privilege vulnerability exists in the way that the tapisrv.dll handles objects in me
An elevation of privilege vulnerability exists in the way that the tapisrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0739.
nvd
CVE-2020-1249P3HIGHCVSS 7.8v2019v2019 (Core installation)2020-07-14
CVE-2020-1249 [HIGH] CVE-2020-1249: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.
nvd
CVE-2020-0857P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-03-12
CVE-2020-0857 [HIGH] CVE-2020-0857: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1463P3HIGHCVSS 7.8v2019v2019 (Core installation)+2 more2020-07-14
CVE-2020-1463 [HIGH] CVE-2020-1463: An elevation of privilege vulnerability exists in the way that the SharedStream Library handles obje
An elevation of privilege vulnerability exists in the way that the SharedStream Library handles objects in memory, aka 'Windows SharedStream Library Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0822P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0822 [HIGH] CVE-2020-0822: An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly h
An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations, aka 'Windows Language Pack Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1385P3HIGHCVSS 7.8v2019v2019 (Core installation)+6 more2020-07-14
CVE-2020-1385 [HIGH] CVE-2020-1385: An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles
An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles objects in memory, aka 'Windows Credential Picker Elevation of Privilege Vulnerability'.
nvd
CVE-2022-29113P3HIGHCVSS 7.8v20h22022-05-10
CVE-2022-29113 [HIGH] CWE-362 CVE-2022-29113: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2022-21883P3HIGHCVSS 7.5v20h2v20222022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21848P3HIGHCVSS 7.5v20h2v20222022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2021-43219P3HIGHCVSS 7.5v20h2v20222021-12-15
CVE-2021-43219 [HIGH] CVE-2021-43219: DirectX Graphics Kernel File Denial of Service Vulnerability
DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2020-0635P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-01-14
CVE-2020-0635 [HIGH] CWE-269 CVE-2020-0635: An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly h
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644.
nvd
CVE-2019-0802P4MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-04-09
CVE-2019-0802 [MEDIUM] CVE-2019-0802: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0849.
nvd
CVE-2018-8438P4MEDIUMCVSS 6.8v2012-r22018-09-13
CVE-2018-8438 [MEDIUM] CVE-2018-8438: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Windows Hyper-V Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This C
nvd
CVE-2019-0602P4MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-03-05
CVE-2019-0602 [MEDIUM] CVE-2019-0602: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0615, CVE-2019-0616, CVE-2019-0619, CVE-2019-0660, CVE-2019-0664.
nvd
CVE-2022-21889P3HIGHCVSS 7.5v20h2v20222022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890P3HIGHCVSS 7.5v20h2v20222022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2021-43216P3MEDIUMCVSS 6.5v20h2v20222021-12-15
CVE-2021-43216 [MEDIUM] CWE-668 CVE-2021-43216: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd