Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 23 of 36
CVE-2020-0781P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0781 [HIGH] CVE-2020-0781: An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) servi
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783.
nvd
CVE-2020-0940P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-04-15
CVE-2020-0940 [HIGH] CVE-2020-0940: An elevation of privilege vulnerability exists in the way the Windows Push Notification Service hand
An elevation of privilege vulnerability exists in the way the Windows Push Notification Service handles objects in memory, aka 'Windows Push Notification Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1001, CVE-2020-1006, CVE-2020-1017.
nvd
CVE-2020-1004P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-1004 [HIGH] CVE-2020-1004: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0840P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-03-12
CVE-2020-0840 [HIGH] CVE-2020-0840: An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Wind
An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0841, CVE-2020-0849, CVE-2020-0896.
nvd
CVE-2019-1407P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-11-12
CVE-2019-1407 [HIGH] CVE-2019-1407: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1433, CVE-2019-1435, CVE-2019-1437, CVE-2019-1438.
nvd
CVE-2019-1086P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-07-15
CVE-2019-1086 [HIGH] CVE-2019-1086: An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of P
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1087, CVE-2019-1088.
nvd
CVE-2020-0679P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0679 [HIGH] CVE-2020-0679: An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Servic
An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0680, CVE-2020-0682.
nvd
CVE-2020-0666P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0666 [HIGH] CVE-2020-0666: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0667, CVE-2020-0735, CVE-2020-0752.
nvd
CVE-2020-0613P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-01-14
CVE-2020-0613 [HIGH] CVE-2020-0613: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0629, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CV
nvd
CVE-2020-1135P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+1 more2020-05-21
CVE-2020-1135 [HIGH] CVE-2020-1135: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1392P3HIGHCVSS 7.8v2012v2012 (Core installation)+2 more2019-11-12
CVE-2019-1392 [HIGH] CVE-2019-1392: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1388P3HIGHCVSS 7.8v2019v2019 (Core installation)+2 more2020-07-14
CVE-2020-1388 [HIGH] CVE-2020-1388: An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in mem
An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1392, CVE-2020-1394, CVE-2020-1395.
nvd
CVE-2020-0737P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-02-11
CVE-2020-0737 [HIGH] CVE-2020-0737: An elevation of privilege vulnerability exists in the way that the tapisrv.dll handles objects in me
An elevation of privilege vulnerability exists in the way that the tapisrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0739.
nvd
CVE-2020-1249P3HIGHCVSS 7.8v2019v2019 (Core installation)2020-07-14
CVE-2020-1249 [HIGH] CVE-2020-1249: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1413, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.
nvd
CVE-2020-0857P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+7 more2020-03-12
CVE-2020-0857 [HIGH] CVE-2020-0857: An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles ob
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0822P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0822 [HIGH] CVE-2020-0822: An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly h
An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations, aka 'Windows Language Pack Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1077P3HIGHCVSS 7.8vversion 1803 (Core Installation)v2019+3 more2020-05-21
CVE-2020-1077 [HIGH] CVE-2020-1077: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1086, CVE-2020-1090, CVE-2020-1125, CVE-2020-1139, CVE-2020-1149, CVE-2020-1151, CVE-2020-1155, CVE-2020-1156, CVE-2020-1157, CVE-2020-1158, CVE-2020-1164.
nvd
CVE-2022-29113P3HIGHCVSS 7.8v20h22022-05-10
CVE-2022-29113 [HIGH] CWE-362 CVE-2022-29113: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2022-21883P3HIGHCVSS 7.5v20h2v20222022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21848P3HIGHCVSS 7.5v20h2v20222022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd