Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 3 of 36
CVE-2020-0668P3HIGHCVSS 7.8PoCvversion 1803 (Core Installation)v2019+1 more2020-02-11
CVE-2020-0668 [HIGH] CWE-732 CVE-2020-0668: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.
nvd
CVE-2019-0785P2CRITICALCVSS 9.8v2012v2012 (Core installation)+7 more2019-07-15
CVE-2019-0785 [CRITICAL] CWE-787 CVE-2019-0785: A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends s
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
nvd
CVE-2022-23270P2HIGHCVSS 8.1v20222022-05-10
CVE-2022-23270 [HIGH] CVE-2022-23270: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2020-1421P2HIGHCVSS 8.8v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1421 [HIGH] CWE-843 CVE-2020-1421: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2019-0618P2HIGHCVSS 8.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-03-05
CVE-2019-0618 [HIGH] CVE-2019-0618: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.
nvd
CVE-2020-1300P2HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1300 [HIGH] CVE-2020-1300: A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses
nvd
CVE-2020-0655P2HIGHCVSS 8.0vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0655 [HIGH] CVE-2020-0655: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Termin
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
nvd
CVE-2019-0697P2CRITICALCVSS 9.8vversion 1803 (Core Installation)v2019+1 more2019-04-09
CVE-2019-0697 [CRITICAL] CWE-787 CVE-2019-0697: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.
nvd
CVE-2018-8420P2HIGHCVSS 8.8v2008-r2v2008-sp2+5 more2018-09-13
CVE-2018-8420 [HIGH] CWE-611 CVE-2018-8420: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 S
nvd
CVE-2020-1301P2HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1301 [HIGH] CVE-2020-1301: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
nvd
CVE-2019-0725P2CRITICALCVSS 9.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-05-16
CVE-2019-0725 [CRITICAL] CWE-787 CVE-2019-0725: A memory corruption vulnerability exists in the Windows Server DHCP service when processing speciall
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
nvd
CVE-2019-0732P3HIGHCVSS 7.8PoCv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-04-09
CVE-2019-0732 [HIGH] CWE-863 CVE-2019-0732: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass De
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1476P3HIGHCVSS 7.8PoCvversion 1803 (Core Installation)v2019+1 more2019-12-10
CVE-2019-1476 [HIGH] CVE-2019-1476: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improp
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483.
nvd
CVE-2018-8410P3HIGHCVSS 7.8PoCv2008-r2v2008-sp2+5 more2018-09-13
CVE-2018-8410 [HIGH] CWE-404 CVE-2018-8410: An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles regist
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Server
nvd
CVE-2019-0730P3HIGHCVSS 7.8PoCvversion 1709 (Core Installation)vversion 1803 (Core Installation)+2 more2019-04-09
CVE-2019-0730 [HIGH] CWE-264 CVE-2019-0730: An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV dr
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.
nvd
CVE-2019-0735P3HIGHCVSS 7.8PoCv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-04-09
CVE-2019-0735 [HIGH] CWE-269 CVE-2019-0735: An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CS
An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'.
nvd
CVE-2018-0877P3HIGHCVSS 7.8PoCv17092018-03-14
CVE-2018-0877 [HIGH] CVE-2018-0877: The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016
The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how file paths are managed, aka "Windows Desktop Bridge VFS Elevation of Privilege Vulnerability".
nvd
CVE-2019-1244P3MEDIUMCVSS 6.5PoCvversion 1803 (Core Installation)v2019+1 more2019-09-11
CVE-2019-1244 [MEDIUM] CWE-200 CVE-2019-1244: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1245, CVE-2019-1251.
nvd
CVE-2022-23285P2HIGHCVSS 8.8v20222022-03-09
CVE-2022-23285 [HIGH] CVE-2022-23285: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2019-0881P3HIGHCVSS 7.8PoCv2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-05-16
CVE-2019-0881 [HIGH] CWE-522 CVE-2019-0881: An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumer
An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd