Msrc Windows Server Version 1709 vulnerabilities

366 known vulnerabilities affecting msrc/windows_server_version_1709.

Total CVEs
366
CISA KEV
16
actively exploited
Public exploits
65
Exploited in wild
19
Severity breakdown
CRITICAL3HIGH166MEDIUM186LOW11

Vulnerabilities

Page 1 of 19
CVE-2019-1406MEDIUMCVSS 6.72019-11-12
CVE-2019-1406 [HIGH] Jet Database Engine Remote Code Execution Vulnerability Jet Database Engine Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the v
msrc
CVE-2019-1399MEDIUMCVSS 5.42019-11-12
CVE-2019-1399 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability Description: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host ma
msrc
CVE-2019-9506CRITICALCVSS 9.32019-08-13
CVE-2019-9506 [HIGH] Encryption Key Negotiation of Bluetooth Vulnerability Encryption Key Negotiation of Bluetooth Vulnerability Description: Executive Summary Microsoft is aware of the Bluetooth BR/EDR (basic rate/enhanced data rate, known as "Bluetooth Classic") key negotiation vulnerability that exists at the hardware specification level of any BR/EDR Bluetooth device. An attacker could potentially be able to negotiate the offered key length down to 1 byte of entropy, from a maximum of 16 by
msrc
CVE-2019-9513HIGHCVSS 7.52019-08-13
CVE-2019-9513 [HIGH] HTTP/2 Server Denial of Service Vulnerability HTTP/2 Server Denial of Service Vulnerability Description: A denial of service vulnerability exists in the HTTP/2 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP/2 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive. To exploit this vulnerability, an unauthenticated attacker could send a sp
msrc
CVE-2019-9512HIGHCVSS 7.52019-08-13
CVE-2019-9512 [HIGH] HTTP/2 Server Denial of Service Vulnerability HTTP/2 Server Denial of Service Vulnerability Description: A denial of service vulnerability exists in the HTTP/2 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP/2 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive. To exploit this vulnerability, an unauthenticated attacker could send a sp
msrc
CVE-2019-9514HIGHCVSS 7.52019-08-13
CVE-2019-9514 [HIGH] HTTP/2 Server Denial of Service Vulnerability HTTP/2 Server Denial of Service Vulnerability Description: A denial of service vulnerability exists in the HTTP/2 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP/2 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive. To exploit this vulnerability, an unauthenticated attacker could send a sp
msrc
CVE-2019-9511HIGHCVSS 7.52019-08-13
CVE-2019-9511 [HIGH] HTTP/2 Server Denial of Service Vulnerability HTTP/2 Server Denial of Service Vulnerability Description: A denial of service vulnerability exists in the HTTP/2 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP/2 requests. An attacker who successfully exploited the vulnerability could create a denial of service condition, causing the target system to become unresponsive. To exploit this vulnerability, an unauthenticated attacker could send a sp
msrc
CVE-2019-1064HIGHCVSS 7.8KEV2019-06-11
CVE-2019-1064 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have to log on to the s
msrc
CVE-2019-0879HIGHCVSS 7.82019-04-09
CVE-2019-0879 [HIGH] Jet Database Engine Remote Code Execution Vulnerability Jet Database Engine Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the v
msrc
CVE-2019-0685HIGHCVSS 7.82019-04-09
CVE-2019-0685 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an
msrc
CVE-2019-0851HIGHCVSS 7.82019-04-09
CVE-2019-0851 [HIGH] Jet Database Engine Remote Code Execution Vulnerability Jet Database Engine Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the v
msrc
CVE-2019-0853HIGHCVSS 7.82019-04-09
CVE-2019-0853 [HIGH] GDI+ Remote Code Execution Vulnerability GDI+ Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are conf
msrc
CVE-2019-0859HIGHCVSS 7.8KEV2019-04-09
CVE-2019-0859 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an
msrc
CVE-2019-0786HIGHCVSS 7.82019-04-09
CVE-2019-0786 [CRITICAL] Hyper-V vSMB Remote Code Execution Vulnerability Hyper-V vSMB Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data. An attacker who successfully exploited these vulnerabilities could execute arbitrary code on a target operating system. To exploit these vulnerabilities, an attacker running inside a virtual machine could run a specially crafted applic
msrc
CVE-2019-0794HIGHCVSS 7.82019-04-09
CVE-2019-0794 [HIGH] OLE Automation Remote Code Execution Vulnerability OLE Automation Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when OLE automation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could gain execution on the victim system. To exploit the vulnerability, an attacker could host a specially crafted website designed to invoke OLE automation through a web browser. However, an attacker w
msrc
CVE-2019-0845HIGHCVSS 7.52019-04-09
CVE-2019-0845 [HIGH] Windows IOleCvt Interface Remote Code Execution Vulnerability Windows IOleCvt Interface Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. In a web-based attack scenario, an attacker could host a specially crafted website designed to exploit the vuln
msrc
CVE-2019-0735HIGHCVSS 7.0PoC2019-04-09
CVE-2019-0735 [HIGH] Windows CSRSS Elevation of Privilege Vulnerability Windows CSRSS Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit th
msrc
CVE-2019-0877HIGHCVSS 7.82019-04-09
CVE-2019-0877 [HIGH] Jet Database Engine Remote Code Execution Vulnerability Jet Database Engine Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the v
msrc
CVE-2019-0803HIGHCVSS 7.0KEVPoC2019-04-09
CVE-2019-0803 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an
msrc
CVE-2019-0790HIGHCVSS 7.82019-04-09
CVE-2019-0790 [HIGH] MS XML Remote Code Execution Vulnerability MS XML Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the vulnerability, an attacker could host a specially crafted website designed to invoke MSXML through a web browser. Howe
msrc
1 / 19Next →