Microsoft Windows Server vulnerabilities
670 known vulnerabilities affecting microsoft/windows_server.
Total CVEs
670
CISA KEV
22
actively exploited
Public exploits
37
Exploited in wild
34
Severity breakdown
CRITICAL26HIGH432MEDIUM208LOW4
Vulnerabilities
Page 7 of 34
CVE-2020-0684P3HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-03-12
CVE-2020-0684 [HIGH] CVE-2020-0684: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2020-1032P3CRITICALCVSS 9.0v2016v2016 (Core installation)+6 more2020-07-14
CVE-2020-1032 [CRITICAL] CWE-20 CVE-2020-1032: A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to pr
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
nvd
CVE-2021-42291P3HIGHCVSS 8.8v20h2v2012-r22021-11-10
CVE-2021-42291 [HIGH] CWE-269 CVE-2021-42291: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2021-42282P3HIGHCVSS 8.8v20h22021-11-10
CVE-2021-42282 [HIGH] CWE-269 CVE-2021-42282: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2019-0856P3HIGHCVSS 7.2v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+16 more2019-04-09
CVE-2019-0856 [HIGH] CVE-2019-0856: A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
nvd
CVE-2022-24508P3HIGHCVSS 8.8v20h22022-03-09
CVE-2022-24508 [HIGH] CVE-2022-24508: Win32 File Enumeration Remote Code Execution Vulnerability
Win32 File Enumeration Remote Code Execution Vulnerability
nvd
CVE-2019-1252P3MEDIUMCVSS 6.5v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1252 [MEDIUM] CWE-200 CVE-2019-1252: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.
nvd
CVE-2020-0690P3CRITICALCVSS 9.8vversion 1803 (Core Installation)v2019+3 more2020-03-12
CVE-2020-0690 [CRITICAL] CVE-2020-0690: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2022-21851P3HIGHCVSS 8.8v20h2v20222022-01-11
CVE-2022-21851 [HIGH] CVE-2022-21851: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-21850P3HIGHCVSS 8.8v20h2v20222022-01-11
CVE-2022-21850 [HIGH] CVE-2022-21850: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-29139P3HIGHCVSS 8.8v20h22022-05-10
CVE-2022-29139 [HIGH] CVE-2022-29139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-21893P3HIGHCVSS 8.0v20h2v20222022-01-11
CVE-2022-21893 [HIGH] CVE-2022-21893: Remote Desktop Protocol Remote Code Execution Vulnerability
Remote Desktop Protocol Remote Code Execution Vulnerability
nvd
CVE-2017-11830P4MEDIUMCVSS 5.3PoCv17092017-11-15
CVE-2017-11830 [MEDIUM] CWE-367 CVE-2017-11830: Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to make an unsigned file appear to be signed, due to a security feature bypass, aka "Device Guard Security Feature Bypass Vulnerability".
nvd
CVE-2019-1280P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-09-11
CVE-2019-1280 [HIGH] CWE-59 CVE-2019-1280: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2020-1317P3HIGHCVSS 8.8vversion 1803 (Core Installation)v2019+15 more2020-06-09
CVE-2020-1317 [HIGH] CVE-2020-1317: An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Grou
An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.
nvd
CVE-2021-40461P3CRITICALCVSS 9.0v20h22021-10-13
CVE-2021-40461 [CRITICAL] CVE-2021-40461: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2020-1374P3HIGHCVSS 7.5v2019v2019 (Core installation)+8 more2020-07-14
CVE-2020-1374 [HIGH] CVE-2020-1374: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2020-1408P3HIGHCVSS 8.8v2019v2019 (Core installation)+12 more2020-07-14
CVE-2020-1408 [HIGH] CWE-346 CVE-2020-1408: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2019-0889P3HIGHCVSS 7.8v2008 R2 for x64-based Systems Service Pack 1 (Core installation)v2008 R2 for Itanium-Based Systems Service Pack 1+15 more2019-05-16
CVE-2019-0889 [HIGH] CVE-2019-0889: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2018-0883P3HIGHCVSS 7.5v17092018-03-14
CVE-2018-0883 [HIGH] CVE-2018-0883: Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how file copy destinations are validated, aka "Windows Shell Remote Code Execution Vulnerabil
nvd