Microsoft Windows Server vulnerabilities
670 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4
Vulnerabilities
Page 6 of 34
CVE-2019-0756P3HIGHCVSS 8.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+6 more2019-04-09
CVE-2019-0756 [HIGH] CWE-611 CVE-2019-0756: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2019-0787P3HIGHCVSS 8.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-0787 [HIGH] CVE-2019-0787: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0788, CVE-2019-1290, CVE-2019-1291.
nvd
CVE-2019-1439P3MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-11-12
CVE-2019-1439 [MEDIUM] CWE-200 CVE-2019-1439: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-0786P3CRITICALCVSS 9.8vversion 1709 (Core Installation)vversion 1803 (Core Installation)+2 more2019-04-09
CVE-2019-0786 [CRITICAL] CWE-20 CVE-2019-0786: An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server wh
An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privilege Vulnerability'.
nvd
CVE-2022-29137P3HIGHCVSS 8.8v20h22022-05-10
CVE-2022-29137 [HIGH] CVE-2022-29137: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22014P3HIGHCVSS 8.8v20222022-05-10
CVE-2022-22014 [HIGH] CVE-2022-22014: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22013P3HIGHCVSS 8.8v20222022-05-10
CVE-2022-22013 [HIGH] CVE-2022-22013: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2019-1166P3MEDIUMCVSS 5.9v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-10-10
CVE-2019-1166 [MEDIUM] CWE-354 CVE-2019-1166: A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to s
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
nvd
CVE-2019-0719P3CRITICALCVSS 9.1vversion 1803 (Core Installation)v2019+1 more2019-11-12
CVE-2019-0719 [CRITICAL] CWE-20 CVE-2019-0719: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fa
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.
nvd
CVE-2020-1286P3HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+1 more2020-06-09
CVE-2020-1286 [HIGH] CWE-20 CVE-2020-1286: A remote code execution vulnerability exists when the Windows Shell does not properly validate file
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.
nvd
CVE-2019-1419P3HIGHCVSS 8.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-11-12
CVE-2019-1419 [HIGH] CVE-2019-1419: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manage
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1456.
nvd
CVE-2019-1102P3HIGHCVSS 8.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-07-15
CVE-2019-1102 [HIGH] CVE-2019-1102: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2020-1412P3HIGHCVSS 8.8v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1412 [HIGH] CWE-269 CVE-2020-1412: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2021-43215P3CRITICALCVSS 9.8v20h2v20222021-12-15
CVE-2021-43215 [CRITICAL] CWE-787 CVE-2021-43215: iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
nvd
CVE-2022-26927P3HIGHCVSS 8.8v20222022-05-10
CVE-2022-26927 [HIGH] CVE-2022-26927: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2019-1311P3HIGHCVSS 7.8v2012v2012 (Core installation)+7 more2019-10-10
CVE-2019-1311 [HIGH] CVE-2019-1311: A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects
A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
nvd
CVE-2022-21881P3HIGHCVSS 7.8v20h2v20222022-01-11
CVE-2022-21881 [HIGH] CWE-362 CVE-2022-21881: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-21922P3HIGHCVSS 8.8v20h2v20222022-01-11
CVE-2022-21922 [HIGH] CVE-2022-21922: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-23294P3HIGHCVSS 8.8v20h2v20222022-03-09
CVE-2022-23294 [HIGH] CVE-2022-23294: Windows Event Tracing Remote Code Execution Vulnerability
Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2018-0825P3HIGHCVSS 7.5v17092018-02-15
CVE-2018-0825 [HIGH] CVE-2018-0825: StructuredQuery in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Window
StructuredQuery in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how objects are handled in memory, aka "StructuredQuery Remote Code Execution Vulnerability"
nvd