cbcvebase.

Microsoft Windows Server vulnerabilities

670 known vulnerabilities affecting microsoft/windows_server.

Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4

Vulnerabilities

Page 23 of 34
CVE-2021-43237P3HIGHCVSS 7.3v20h2v20222021-12-15
CVE-2021-43237 [HIGH] CWE-59 CVE-2021-43237: Windows Setup Elevation of Privilege Vulnerability Windows Setup Elevation of Privilege Vulnerability
nvd
CVE-2022-21863P4HIGHCVSS 7.0v20h2v20222022-01-11
CVE-2022-21863 [HIGH] CVE-2022-21863: Windows StateRepository API Server file Elevation of Privilege Vulnerability Windows StateRepository API Server file Elevation of Privilege Vulnerability
nvd
CVE-2019-1094P4MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+6 more2019-07-15
CVE-2019-1094 [MEDIUM] CWE-200 CVE-2019-1094: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2020-0853P4MEDIUMCVSS 6.5vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0853 [MEDIUM] CVE-2020-0853: An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails t An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.
nvd
CVE-2019-1230P4MEDIUMCVSS 6.8vversion 1803 (Core Installation)v2019+1 more2019-10-10
CVE-2019-1230 [MEDIUM] CWE-20 CVE-2019-1230: An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host ope An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2020-1397P4MEDIUMCVSS 6.5v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1397 [MEDIUM] CVE-2020-1397: An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails t An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.
nvd
CVE-2018-8422P4MEDIUMCVSS 6.5v2008-r22018-09-13
CVE-2018-8422 [MEDIUM] CWE-200 CVE-2018-8422: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.
nvd
CVE-2019-1411P4MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-11-12
CVE-2019-1411 [MEDIUM] CWE-125 CVE-2019-1411: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5v20222022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2022-22015P4MEDIUMCVSS 6.5v20222022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2022-21864P4HIGHCVSS 7.0v20h2v20222022-01-11
CVE-2022-21864 [HIGH] CVE-2022-21864: Windows UI Immersive Server API Elevation of Privilege Vulnerability Windows UI Immersive Server API Elevation of Privilege Vulnerability
nvd
CVE-2022-21860P4HIGHCVSS 7.0v20h2v20222022-01-11
CVE-2022-21860 [HIGH] CVE-2022-21860: Windows AppContracts API Server Elevation of Privilege Vulnerability Windows AppContracts API Server Elevation of Privilege Vulnerability
nvd
CVE-2019-0683P4MEDIUMCVSS 5.9v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+6 more2019-04-09
CVE-2019-0683 [MEDIUM] CWE-276 CVE-2019-0683: An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default se An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
nvd
CVE-2022-23298P4HIGHCVSS 7.0v20h2v20222022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-0975P4MEDIUMCVSS 6.3v2012 R2v2012 R2 (Core installation)+5 more2019-07-15
CVE-2019-0975 [MEDIUM] CVE-2019-0975: A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) impr A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses. To exploit this vulnerability, an attacker would have to convince a victim ADFS administrator to update the list of banned IP addresses. This security update corrects how ADFS updates its list of banned IP address
nvd
CVE-2019-0614P4MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+4 more2019-04-08
CVE-2019-0614 [MEDIUM] CVE-2019-0614: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774.
nvd
CVE-2019-0712P4MEDIUMCVSS 6.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for x64-based Systems Service Pack 1+11 more2019-11-12
CVE-2019-0712 [MEDIUM] CWE-20 CVE-2019-0712: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309, CVE-2019-1310, CVE-2019-1399.
nvd
CVE-2020-0952P4MEDIUMCVSS 6.5vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0952 [MEDIUM] CVE-2020-0952: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2020-1232P4MEDIUMCVSS 6.5vversion 1803 (Core Installation)v2019+3 more2020-06-09
CVE-2020-1232 [MEDIUM] CWE-125 CVE-2020-1232: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
nvd
CVE-2020-1348P4MEDIUMCVSS 6.5vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1348 [MEDIUM] CVE-2020-1348: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
Microsoft Windows Server vulnerabilities | cvebase