Msrc Windows Server Version 1803 vulnerabilities
568 known vulnerabilities affecting msrc/windows_server_version_1803.
Total CVEs
568
CISA KEV
22
actively exploited
Public exploits
44
Exploited in wild
25
Severity breakdown
CRITICAL12HIGH376MEDIUM174LOW6
Vulnerabilities
Page 15 of 29
CVE-2019-1060MEDIUMCVSS 6.42019-10-08
CVE-2019-1060 [HIGH] MS XML Remote Code Execution Vulnerability
MS XML Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system.
To exploit the vulnerability, an attacker could host a specially crafted website designed to invoke MSXML through a web browser. Howe
msrc
CVE-2019-1325MEDIUMCVSS 5.52019-10-08
CVE-2019-1325 [MEDIUM] Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the operating system improperly handles specific local calls within Windows 7 for 32-bit systems. When this vulnerability is exploited within other versions of Windows it can cause a denial of
msrc
CVE-2019-1321MEDIUMCVSS 5.82019-10-08
CVE-2019-1321 [HIGH] Microsoft Windows CloudStore Elevation of Privilege Vulnerability
Microsoft Windows CloudStore Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL). An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
To exploit this vulnerability, an attacker would first have to log on to th
msrc
CVE-2019-1230MEDIUMCVSS 6.82019-10-08
CVE-2019-1230 [MEDIUM] Hyper-V Information Disclosure Vulnerability
Hyper-V Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disc
msrc
CVE-2019-1368MEDIUMCVSS 4.92019-10-08
CVE-2019-1368 [MEDIUM] Windows Secure Boot Security Feature Bypass Vulnerability
Windows Secure Boot Security Feature Bypass Vulnerability
Description: A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality. An attacker who successfully exploited this vulnerability could disclose protected kernel memory.
To exploit the vulnerability, an attacker must gain physical access to the target system prior to the next system reboot.
The security
msrc
CVE-2019-1343MEDIUMCVSS 6.5PoC2019-10-08
CVE-2019-1343 [MEDIUM] Windows Denial of Service Vulnerability
Windows Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specific file on a network s
msrc
CVE-2019-1317MEDIUMCVSS 6.42019-10-08
CVE-2019-1317 [HIGH] Microsoft Windows Denial of Service Vulnerability
Microsoft Windows Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would allow an attacker to ove
msrc
CVE-2019-1334MEDIUMCVSS 4.72019-10-08
CVE-2019-1334 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
msrc
CVE-2019-1347MEDIUMCVSS 5.7PoC2019-10-08
CVE-2019-1347 [MEDIUM] Windows Denial of Service Vulnerability
Windows Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specific file on a network s
msrc
CVE-2019-1232HIGHCVSS 7.82019-09-10
CVE-2019-1232 [HIGH] Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.
An attacker with unprivileged access to a vulnerable system could e
msrc
CVE-2019-1253HIGHCVSS 7.8KEVPoC2019-09-10
CVE-2019-1253 [HIGH] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting how AppX Deplo
msrc
CVE-2019-1287HIGHCVSS 7.82019-09-10
CVE-2019-1287 [HIGH] Windows Network Connectivity Assistant Elevation of Privilege Vulnerability
Windows Network Connectivity Assistant Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that the Windows Network Connectivity Assistant handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a sp
msrc
CVE-2019-1278HIGHCVSS 7.82019-09-10
CVE-2019-1278 [HIGH] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability by ensuring
msrc
CVE-2019-1277HIGHCVSS 7.82019-09-10
CVE-2019-1277 [HIGH] Windows Audio Service Elevation of Privilege Vulnerability
Windows Audio Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows Audio Service when a malformed parameter is processed. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges when used in conjunction with another vulnerability.
To exploit the vulnerability, an attacker could run a specially crafted ap
msrc
CVE-2019-1303HIGHCVSS 7.82019-09-10
CVE-2019-1303 [HIGH] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting how AppX Deplo
msrc
CVE-2019-1289HIGHCVSS 7.02019-09-10
CVE-2019-1289 [MEDIUM] Windows Update Delivery Optimization Elevation of Privilege Vulnerability
Windows Update Delivery Optimization Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions. An attacker who successfully exploited the vulnerability could overwrite files that require higher privileges than what the attacker already has.
To exploit this vulnerabil
msrc
CVE-2019-1267HIGHCVSS 7.32019-09-10
CVE-2019-1267 [HIGH] Microsoft Compatibility Appraiser Elevation of Privilege Vulnerability
Microsoft Compatibility Appraiser Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install p
msrc
CVE-2019-1290HIGHCVSS 7.52019-09-10
CVE-2019-1290 [HIGH] Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. An attacker who successfully exploited this vulnerability could execute arbitrary code on the computer of the connecting client. An attacker could then install programs; view, change, or delete data; or create new accounts
msrc
CVE-2019-1292HIGHCVSS 7.82019-09-10
CVE-2019-1292 [MEDIUM] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate permissions.
To exploit this vulnerability, an attacker would first have to log on to the system. An att
msrc
CVE-2019-1273HIGHCVSS 8.22019-09-10
CVE-2019-1273 [MEDIUM] Active Directory Federation Services XSS Vulnerability
Active Directory Federation Services XSS Vulnerability
Description: A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS server.
The attacker who successfully exploited the vulnerability could then perform c
msrc