Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 4 of 36
CVE-2020-0729P2HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-02-11
CVE-2020-0729 [HIGH] CVE-2020-0729: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2019-1343P3MEDIUMCVSS 6.5PoCv2012 R2v2012 R2 (Core installation)+5 more2019-10-10
CVE-2019-1343 [MEDIUM] CVE-2019-1343: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.
nvd
CVE-2019-1358P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-10-10
CVE-2019-1358 [HIGH] CVE-2019-1358: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1359.
nvd
CVE-2009-1133P2CRITICALCVSS 9.3v20032009-08-12
CVE-2009-1133 [CRITICAL] CWE-119 CVE-2009-1133: Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client
Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
nvd
CVE-2022-21990P2HIGHCVSS 8.8v20h2v20222022-03-09
CVE-2022-21990 [HIGH] CVE-2022-21990: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2019-0853P2HIGHCVSS 8.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-04-09
CVE-2019-0853 [HIGH] CWE-824 CVE-2019-0853: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2022-21849P2CRITICALCVSS 9.8v20h2v20222022-01-11
CVE-2022-21849 [CRITICAL] CVE-2022-21849: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2019-0603P3HIGHCVSS 7.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-04-08
CVE-2019-0603 [HIGH] CVE-2019-0603: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to
nvd
CVE-2022-22012P2CRITICALCVSS 9.8v20222022-05-10
CVE-2022-22012 [CRITICAL] CVE-2022-22012: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29130P2CRITICALCVSS 9.8v20h22022-05-10
CVE-2022-29130 [CRITICAL] CVE-2022-29130: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2009-0568P2CRITICALCVSS 10.0v20082009-06-10
CVE-2009-0568 [CRITICAL] CWE-264 CVE-2009-0568: The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2,
The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL inte
nvd
CVE-2020-1436P2HIGHCVSS 8.8v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1436 [HIGH] CWE-787 CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
nvd
CVE-2021-43217P2CRITICALCVSS 9.8v20h2v20222021-12-15
CVE-2021-43217 [CRITICAL] CVE-2021-43217: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
nvd
CVE-2009-0230P3CRITICALCVSS 9.0v20082009-06-10
CVE-2009-0230 [CRITICAL] CWE-264 CVE-2009-0230: The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold
The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
nvd
CVE-2019-1468P3HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2019-12-10
CVE-2019-1468 [HIGH] CWE-787 CVE-2019-1468: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2019-1333P2HIGHCVSS 8.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-10-10
CVE-2019-1333 [HIGH] CVE-2019-1333: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2018-8332P3HIGHCVSS 8.8v2008-r2v2008-sp2+5 more2018-09-13
CVE-2018-8332 [HIGH] CVE-2018-8332: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows
nvd
CVE-2020-0687P2HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0687 [HIGH] CVE-2020-0687: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2022-21984P2HIGHCVSS 8.8v20h2v20222022-02-09
CVE-2022-21984 [HIGH] CVE-2022-21984: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2020-0964P2HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-04-15
CVE-2020-0964 [HIGH] CVE-2020-0964: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd