cbcvebase.

Microsoft Windows Server Version 20H2 vulnerabilities

965 known vulnerabilities affecting microsoft/windows_server_version_20h2.

Total CVEs
965
CISA KEV
39
actively exploited
Public exploits
32
Exploited in wild
53
Severity breakdown
CRITICAL44HIGH689MEDIUM229LOW3

Vulnerabilities

Page 33 of 49
CVE-2022-30202P3HIGHCVSS 7.0≥ 10.0.0, < 10.0.19042.18262022-07-12
CVE-2022-30202 [HIGH] CVE-2022-30202: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2021-34490P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.11102021-07-14
CVE-2021-34490 [HIGH] CVE-2021-34490: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2021-33772P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.11102021-07-14
CVE-2021-33772 [HIGH] CVE-2021-33772: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2022-30152P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.17662022-06-15
CVE-2022-30152 [HIGH] CVE-2022-30152: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2022-22040P3HIGHCVSS 7.3≥ 10.0.0, < 10.0.19042.18262022-07-12
CVE-2022-22040 [HIGH] CVE-2022-22040: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
nvd
CVE-2022-30214P3MEDIUMCVSS 6.6≥ 10.0.0, < 10.0.19042.18262022-07-12
CVE-2022-30214 [MEDIUM] CWE-362 CVE-2022-30214: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-31968P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.10522021-06-08
CVE-2021-31968 [HIGH] CVE-2021-31968: Windows Remote Desktop Services Denial of Service Vulnerability Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2021-33785P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.11102021-07-14
CVE-2021-33785 [HIGH] CVE-2021-33785: Windows AF_UNIX Socket Provider Denial of Service Vulnerability Windows AF_UNIX Socket Provider Denial of Service Vulnerability
nvd
CVE-2022-21889P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.14662022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.14662022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-34701P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.18892022-08-09
CVE-2022-34701 [HIGH] CWE-400 CVE-2022-34701: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2022-35769P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19042.18892022-08-09
CVE-2022-35769 [HIGH] CWE-400 CVE-2022-35769: Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
nvd
CVE-2020-16997P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-11-11
CVE-2020-16997 [MEDIUM] CVE-2020-16997: Remote Desktop Protocol Server Information Disclosure Vulnerability Remote Desktop Protocol Server Information Disclosure Vulnerability
nvd
CVE-2021-43216P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19042.14152021-12-15
CVE-2021-43216 [MEDIUM] CWE-668 CVE-2021-43216: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2021-43237P3HIGHCVSS 7.3≥ 10.0.0, < 10.0.19042.14152021-12-15
CVE-2021-43237 [HIGH] CWE-59 CVE-2021-43237: Windows Setup Elevation of Privilege Vulnerability Windows Setup Elevation of Privilege Vulnerability
nvd
CVE-2022-35822P3HIGHCVSS 7.1≥ 10.0.0, < 10.0.19042.18892022-08-15
CVE-2022-35822 [HIGH] CVE-2022-35822: Windows Defender Credential Guard Security Feature Bypass Vulnerability Windows Defender Credential Guard Security Feature Bypass Vulnerability
nvd
CVE-2022-21863P4HIGHCVSS 7.0≥ 10.0.0, < 10.0.19042.14662022-01-11
CVE-2022-21863 [HIGH] CVE-2022-21863: Windows StateRepository API Server file Elevation of Privilege Vulnerability Windows StateRepository API Server file Elevation of Privilege Vulnerability
nvd
CVE-2022-24490P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19042.16452022-04-15
CVE-2022-24490 [MEDIUM] CVE-2022-24490: Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19042.17062022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd