Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 30 of 36
CVE-2022-29122P4MEDIUMCVSS 6.5v20h2v20222022-05-10
CVE-2022-29122 [MEDIUM] CVE-2022-29122: Windows Clustered Shared Volume Information Disclosure Vulnerability
Windows Clustered Shared Volume Information Disclosure Vulnerability
nvd
CVE-2022-29123P4MEDIUMCVSS 6.5v20h22022-05-10
CVE-2022-29123 [MEDIUM] CVE-2022-29123: Windows Clustered Shared Volume Information Disclosure Vulnerability
Windows Clustered Shared Volume Information Disclosure Vulnerability
nvd
CVE-2020-1267P4MEDIUMCVSS 4.9v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1267 [MEDIUM] CVE-2020-1267: This security update corrects a denial of service in the Local Security Authority Subsystem Service
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'.
nvd
CVE-2018-8445P4MEDIUMCVSS 5.5v18032018-09-13
CVE-2018-8445 [MEDIUM] CVE-2018-8445: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8336, CVE-2018-8419, CVE-2018-8442, CVE-2018-8443, CVE-2018-8446.
nvd
CVE-2019-1293P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+10 more2019-09-11
CVE-2019-1293 [MEDIUM] CWE-200 CVE-2019-1293: An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode dr
An information disclosure vulnerability exists in Windows when the Windows SMB Client kernel-mode driver fails to properly handle objects in memory, aka 'Windows SMB Client Driver Information Disclosure Vulnerability'.
nvd
CVE-2019-0628P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-03-05
CVE-2019-0628 [MEDIUM] CVE-2019-0628: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2019-0636P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-03-05
CVE-2019-0636 [MEDIUM] CVE-2019-0636: An information vulnerability exists when Windows improperly discloses file information, aka 'Windows
An information vulnerability exists when Windows improperly discloses file information, aka 'Windows Information Disclosure Vulnerability'.
nvd
CVE-2019-1363P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+1 more2019-10-10
CVE-2019-1363 [MEDIUM] CWE-200 CVE-2019-1363: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2020-0744P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0744 [MEDIUM] CWE-125 CVE-2020-0744: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-1093P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-07-15
CVE-2019-1093 [MEDIUM] CWE-200 CVE-2019-1093: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1097.
nvd
CVE-2018-0888P4MEDIUMCVSS 5.6v17092018-03-14
CVE-2018-0888 [MEDIUM] CWE-20 CVE-2018-0888: The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how guest operating system input is valida
nvd
CVE-2019-1219P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1219 [MEDIUM] CWE-200 CVE-2019-1219: An information disclosure vulnerability exists when the Windows Transaction Manager improperly handl
An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows Transaction Manager Information Disclosure Vulnerability'.
nvd
CVE-2020-0615P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-01-14
CVE-2020-0615 [MEDIUM] CWE-125 CVE-2020-0615: An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver w
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0639.
nvd
CVE-2019-1436P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+1 more2019-11-12
CVE-2019-1436 [MEDIUM] CWE-200 CVE-2019-1436: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1440.
nvd
CVE-2020-0955P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0955 [MEDIUM] CVE-2020-0955: An information disclosure vulnerability exists when certain central processing units (CPU) speculati
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory, aka 'Windows Kernel Information Disclosure in CPU Memory Access'.
nvd
CVE-2022-21906P4MEDIUMCVSS 5.5v20h2v20222022-01-11
CVE-2022-21906 [MEDIUM] CVE-2022-21906: Windows Defender Application Control Security Feature Bypass Vulnerability
Windows Defender Application Control Security Feature Bypass Vulnerability
nvd
CVE-2019-1289P4MEDIUMCVSS 5.5v2016v2016 (Core installation)+3 more2019-09-11
CVE-2019-1289 [MEDIUM] CWE-863 CVE-2019-1289: An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does no
An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0733P4MEDIUMCVSS 5.3v2016v2016 (Core installation)+3 more2019-05-16
CVE-2019-0733 [MEDIUM] CVE-2019-0733: A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which
A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'.
nvd
CVE-2020-1259P4MEDIUMCVSS 4.3vversion 1803 (Core Installation)v2019+3 more2020-06-09
CVE-2020-1259 [MEDIUM] CVE-2020-1259: A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles
A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1292P4MEDIUMCVSS 4.9v2016v2016 (Core installation)+3 more2019-09-11
CVE-2019-1292 [MEDIUM] CVE-2019-1292: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd