Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 33 of 36
CVE-2020-0736P4MEDIUMCVSS 5.5v2008 for 32-bit Systems Service Pack 2v2008 for 32-bit Systems Service Pack 2 (Core installation)+6 more2020-02-11
CVE-2020-0736 [MEDIUM] CVE-2020-0736: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.
nvd
CVE-2020-0698P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0698 [MEDIUM] CVE-2020-0698: An information disclosure vulnerability exists when the Telephony Service improperly discloses the c
An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'.
nvd
CVE-2020-0716P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+1 more2020-02-11
CVE-2020-0716 [MEDIUM] CVE-2020-0716: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0717.
nvd
CVE-2020-1351P4MEDIUMCVSS 5.5v2019v2019 (Core installation)+8 more2020-07-14
CVE-2020-1351 [MEDIUM] CVE-2020-1351: An information disclosure vulnerability exists when the Windows Graphics component improperly handle
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2020-0982P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0982 [MEDIUM] CVE-2020-0982: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0987, CVE-2020-1005.
nvd
CVE-2020-0608P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-01-14
CVE-2020-0608 [MEDIUM] CVE-2020-0608: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2019-1409P4MEDIUMCVSS 5.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-11-12
CVE-2019-1409 [MEDIUM] CWE-665 CVE-2019-1409: An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime
An information disclosure vulnerability exists when the Windows Remote Procedure Call (RPC) runtime improperly initializes objects in memory, aka 'Windows Remote Procedure Call Information Disclosure Vulnerability'.
nvd
CVE-2020-0622P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2016+1 more2020-01-14
CVE-2020-0622 [MEDIUM] CVE-2020-0622: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2020-0820P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+3 more2020-03-12
CVE-2020-0820 [MEDIUM] CVE-2020-0820: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
nvd
CVE-2020-1296P4MEDIUMCVSS 5.5v2019v2019 (Core installation)2020-06-09
CVE-2020-1296 [MEDIUM] CVE-2020-1296: A vulnerability exists in the way the Windows Diagnostics & feedback settings app handles object
A vulnerability exists in the way the Windows Diagnostics & feedback settings app handles objects in memory, aka 'Windows Diagnostics & feedback Information Disclosure Vulnerability'.
nvd
CVE-2020-1367P4MEDIUMCVSS 5.5v2019v2019 (Core installation)2020-07-14
CVE-2020-1367 [MEDIUM] CVE-2020-1367: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1389, CVE-2020-1419, CVE-2020-1426.
nvd
CVE-2020-1290P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+1 more2020-06-09
CVE-2020-1290 [MEDIUM] CVE-2020-1290: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2020-1072P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1072 [MEDIUM] CVE-2020-1072: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.
nvd
CVE-2022-23281P4MEDIUMCVSS 5.5v20h2v20222022-03-09
CVE-2022-23281 [MEDIUM] CVE-2022-23281: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2020-0779P4MEDIUMCVSS 5.5vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0779 [MEDIUM] CWE-59 CVE-2020-0779: An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process sy
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-0843.
nvd
CVE-2019-1270P4MEDIUMCVSS 5.5v2016v2016 (Core installation)+3 more2019-09-11
CVE-2019-1270 [MEDIUM] CWE-59 CVE-2019-1270: An elevation of privilege vulnerability exists in Windows store installer where WindowsApps director
An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2022-21998P4MEDIUMCVSS 5.5v20h2v20222022-02-09
CVE-2022-21998 [MEDIUM] CVE-2022-21998: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2022-21985P4MEDIUMCVSS 5.5v20h2v20222022-02-09
CVE-2022-21985 [MEDIUM] CVE-2022-21985: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2022-26930P4MEDIUMCVSS 5.5v20222022-05-10
CVE-2022-26930 [MEDIUM] CVE-2022-26930: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2021-43235P4MEDIUMCVSS 5.5v20h2v20222021-12-15
CVE-2021-43235 [MEDIUM] CVE-2021-43235: Storage Spaces Controller Information Disclosure Vulnerability
Storage Spaces Controller Information Disclosure Vulnerability
nvd