Microsoft Windows Server vulnerabilities
670 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4
Vulnerabilities
Page 32 of 34
CVE-2020-1367P4MEDIUMCVSS 5.5v2019v2019 (Core installation)2020-07-14
CVE-2020-1367 [MEDIUM] CVE-2020-1367: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1389, CVE-2020-1419, CVE-2020-1426.
nvd
CVE-2022-23281P4MEDIUMCVSS 5.5v20h2v20222022-03-09
CVE-2022-23281 [MEDIUM] CVE-2022-23281: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2020-0779P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0779 [MEDIUM] CWE-59 CVE-2020-0779: An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process sy
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.
nvd
CVE-2019-1270P4MEDIUMCVSS 5.5v2016v2016 (Core installation)+3 more2019-09-11
CVE-2019-1270 [MEDIUM] CWE-59 CVE-2019-1270: An elevation of privilege vulnerability exists in Windows store installer where WindowsApps director
An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2022-26930P4MEDIUMCVSS 5.5v20222022-05-10
CVE-2022-26930 [MEDIUM] CVE-2022-26930: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2022-21998P4MEDIUMCVSS 5.5v20h2v20222022-02-09
CVE-2022-21998 [MEDIUM] CVE-2022-21998: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2022-21985P4MEDIUMCVSS 5.5v20h2v20222022-02-09
CVE-2022-21985 [MEDIUM] CVE-2022-21985: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2021-43235P4MEDIUMCVSS 5.5v20h2v20222021-12-15
CVE-2021-43235 [MEDIUM] CVE-2021-43235: Storage Spaces Controller Information Disclosure Vulnerability
Storage Spaces Controller Information Disclosure Vulnerability
nvd
CVE-2021-43227P4MEDIUMCVSS 5.5v20h2v20222021-12-15
CVE-2021-43227 [MEDIUM] CVE-2021-43227: Storage Spaces Controller Information Disclosure Vulnerability
Storage Spaces Controller Information Disclosure Vulnerability
nvd
CVE-2017-11842P4MEDIUMCVSS 4.7v17092017-11-15
CVE-2017-11842 [MEDIUM] CWE-200 CVE-2017-11842: Windows kernel in Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and
Windows kernel in Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing a memory address, aka "Windows Kernel Information Disclosure Vulnerabil
nvd
CVE-2018-0904P4MEDIUMCVSS 4.7v17092018-03-14
CVE-2018-0904 [MEDIUM] CWE-200 CVE-2018-0904: The Windows kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, W
The Windows kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows information disclosure vulnerability due to how memory addresses are handled, aka "Windows Kernel Information Disclosure
nvd
CVE-2020-0617P4MEDIUMCVSS 6.0vversion 1803 (Core Installation)v2019+3 more2020-01-14
CVE-2020-0617 [MEDIUM] CWE-20 CVE-2020-0617: A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails t
A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'.
nvd
CVE-2020-0885P4MEDIUMCVSS 4.3vversion 1803 (Core Installation)v2019+10 more2020-03-12
CVE-2020-0885 [MEDIUM] CVE-2020-0885: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2020-1016P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+7 more2020-04-15
CVE-2020-1016 [MEDIUM] CVE-2020-1016: An information disclosure vulnerability exists when the Windows Push Notification Service improperly
An information disclosure vulnerability exists when the Windows Push Notification Service improperly handles objects in memory, aka 'Windows Push Notification Service Information Disclosure Vulnerability'.
nvd
CVE-2022-29114P4MEDIUMCVSS 5.5v20h2v20222022-05-10
CVE-2022-29114 [MEDIUM] CVE-2022-29114: Windows Print Spooler Information Disclosure Vulnerability
Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2020-1296P4MEDIUMCVSS 5.5v2019v2019 (Core installation)2020-06-09
CVE-2020-1296 [MEDIUM] CVE-2020-1296: A vulnerability exists in the way the Windows Diagnostics & feedback settings app handles object
A vulnerability exists in the way the Windows Diagnostics & feedback settings app handles objects in memory, aka 'Windows Diagnostics & feedback Information Disclosure Vulnerability'.
nvd
CVE-2022-29140P4MEDIUMCVSS 5.5v20h22022-05-10
CVE-2022-29140 [MEDIUM] CVE-2022-29140: Windows Print Spooler Information Disclosure Vulnerability
Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2022-29102P4MEDIUMCVSS 5.5v20h22022-05-10
CVE-2022-29102 [MEDIUM] CVE-2022-29102: Windows Failover Cluster Information Disclosure Vulnerability
Windows Failover Cluster Information Disclosure Vulnerability
nvd
CVE-2022-22011P4MEDIUMCVSS 5.5v20222022-05-10
CVE-2022-22011 [MEDIUM] CVE-2022-22011: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-23297P4MEDIUMCVSS 5.5v20h2v20222022-03-09
CVE-2022-23297 [MEDIUM] CVE-2022-23297: Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability
Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability
nvd