Microsoft Windows Server vulnerabilities
670 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4
Vulnerabilities
Page 29 of 34
CVE-2020-0744P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0744 [MEDIUM] CWE-125 CVE-2020-0744: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-1436P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+1 more2019-11-12
CVE-2019-1436 [MEDIUM] CWE-200 CVE-2019-1436: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1440.
nvd
CVE-2019-1093P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-07-15
CVE-2019-1093 [MEDIUM] CWE-200 CVE-2019-1093: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1097.
nvd
CVE-2019-1219P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1219 [MEDIUM] CWE-200 CVE-2019-1219: An information disclosure vulnerability exists when the Windows Transaction Manager improperly handl
An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Manager Information Disclosure Vulnerability'.
nvd
CVE-2020-0615P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-01-14
CVE-2020-0615 [MEDIUM] CWE-125 CVE-2020-0615: An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver w
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0639.
nvd
CVE-2019-1283P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+1 more2019-09-11
CVE-2019-1283 [MEDIUM] CWE-200 CVE-2019-1283: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.
nvd
CVE-2020-0675P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0675 [MEDIUM] CVE-2020-0675: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2019-1381P4MEDIUMCVSS 5.5v2012v2012 (Core installation)+7 more2019-11-12
CVE-2019-1381 [MEDIUM] CWE-200 CVE-2019-1381: An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unp
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'.
nvd
CVE-2020-0658P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0658 [MEDIUM] CVE-2020-0658: An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver w
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'.
nvd
CVE-2022-21906P4MEDIUMCVSS 5.5v20h2v20222022-01-11
CVE-2022-21906 [MEDIUM] CVE-2022-21906: Windows Defender Application Control Security Feature Bypass Vulnerability
Windows Defender Application Control Security Feature Bypass Vulnerability
nvd
CVE-2019-0733P4MEDIUMCVSS 5.3v2016v2016 (Core installation)+3 more2019-05-16
CVE-2019-0733 [MEDIUM] CVE-2019-0733: A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1289P4MEDIUMCVSS 5.5v2016v2016 (Core installation)+3 more2019-09-11
CVE-2019-1289 [MEDIUM] CWE-863 CVE-2019-1289: An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does no
An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1259P4MEDIUMCVSS 4.3vversion 1803 (Core Installation)v2019+3 more2020-06-09
CVE-2020-1259 [MEDIUM] CVE-2020-1259: A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles
A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1292P4MEDIUMCVSS 4.9v2016v2016 (Core installation)+3 more2019-09-11
CVE-2019-1292 [MEDIUM] CVE-2019-1292: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2019-0928P4MEDIUMCVSS 6.2v2016v2016 (Core installation)+1 more2019-09-11
CVE-2019-0928 [MEDIUM] CWE-20 CVE-2019-0928: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
nvd
CVE-2019-1071P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-07-15
CVE-2019-1071 [MEDIUM] CWE-200 CVE-2019-1071: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1073.
nvd
CVE-2019-1334P4MEDIUMCVSS 5.5v2016v2016 (Core installation)+3 more2019-10-10
CVE-2019-1334 [MEDIUM] CWE-200 CVE-2019-1334: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1345.
nvd
CVE-2019-0840P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-04-09
CVE-2019-0840 [MEDIUM] CVE-2019-0840: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0844.
nvd
CVE-2019-0837P4MEDIUMCVSS 5.5vversion 1709 (Core Installation)vversion 1803 (Core Installation)2019-04-09
CVE-2019-0837 [MEDIUM] CVE-2019-0837: An information disclosure vulnerability exists when DirectX improperly handles objects in memory, ak
An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure Vulnerability'.
nvd
CVE-2019-0621P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+8 more2019-03-05
CVE-2019-0621 [MEDIUM] CVE-2019-0621: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0661, CVE-2019-0663.
nvd