Microsoft Windows Server vulnerabilities
705 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
705
CISA KEV
23
actively exploited
Public exploits
39
Exploited in wild
36
Severity breakdown
CRITICAL27HIGH458MEDIUM216LOW4
Vulnerabilities
Page 7 of 36
CVE-2019-1311P3HIGHCVSS 7.8v2012v2012 (Core installation)+7 more2019-10-10
CVE-2019-1311 [HIGH] CVE-2019-1311: A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects
A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
nvd
CVE-2020-1117P3HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+3 more2020-05-21
CVE-2020-1117 [HIGH] CVE-2020-1117: A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll)
A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory, aka 'Microsoft Color Management Remote Code Execution Vulnerability'.
nvd
CVE-2020-1061P3HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1061 [HIGH] CWE-787 CVE-2020-1061: A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles ob
A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory, aka 'Microsoft Script Runtime Remote Code Execution Vulnerability'.
nvd
CVE-2022-21922P3HIGHCVSS 8.8v20h2v20222022-01-11
CVE-2022-21922 [HIGH] CVE-2022-21922: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2020-0684P3HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0684 [HIGH] CVE-2020-0684: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2018-0825P3HIGHCVSS 7.5v17092018-02-15
CVE-2018-0825 [HIGH] CVE-2018-0825: StructuredQuery in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Window
StructuredQuery in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how objects are handled in memory, aka "StructuredQuery Remote Code Execution Vulnerability"
nvd
CVE-2020-1032P3CRITICALCVSS 9.0v2016v2016 (Core installation)+6 more2020-07-14
CVE-2020-1032 [CRITICAL] CWE-20 CVE-2020-1032: A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to pr
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
nvd
CVE-2022-24508P3HIGHCVSS 8.8v20h22022-03-09
CVE-2022-24508 [HIGH] CVE-2022-24508: Win32 File Enumeration Remote Code Execution Vulnerability
Win32 File Enumeration Remote Code Execution Vulnerability
nvd
CVE-2019-0856P3HIGHCVSS 7.2v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-04-09
CVE-2019-0856 [HIGH] CVE-2019-0856: A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
nvd
CVE-2022-29139P3HIGHCVSS 8.8v20h22022-05-10
CVE-2022-29139 [HIGH] CVE-2022-29139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2019-1252P3MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1252 [MEDIUM] CWE-200 CVE-2019-1252: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.
nvd
CVE-2020-1112P3CRITICALCVSS 9.9vversion 1803 (Core Installation)v2019+15 more2020-05-21
CVE-2020-1112 [CRITICAL] CWE-434 CVE-2020-1112: An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Serv
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0690P3CRITICALCVSS 9.8vversion 1803 (Core Installation)v2019+3 more2020-03-12
CVE-2020-0690 [CRITICAL] CVE-2020-0690: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1374P3HIGHCVSS 7.5v2019v2019 (Core installation)+8 more2020-07-14
CVE-2020-1374 [HIGH] CVE-2020-1374: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2017-11830P4MEDIUMCVSS 5.3PoCv17092017-11-15
CVE-2017-11830 [MEDIUM] CWE-367 CVE-2017-11830: Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "Device Guard Security Feature Bypass Vulnerability".
nvd
CVE-2021-42291P3HIGHCVSS 8.8v20h2v20122021-11-10
CVE-2021-42291 [HIGH] CWE-269 CVE-2021-42291: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2021-42282P3HIGHCVSS 8.8v20h22021-11-10
CVE-2021-42282 [HIGH] CWE-269 CVE-2021-42282: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-21851P3HIGHCVSS 8.8v20h2v20222022-01-11
CVE-2022-21851 [HIGH] CVE-2022-21851: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-21850P3HIGHCVSS 8.8v20h2v20222022-01-11
CVE-2022-21850 [HIGH] CVE-2022-21850: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2021-40461P3CRITICALCVSS 9.0v20h22021-10-13
CVE-2021-40461 [CRITICAL] CVE-2021-40461: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd