Msrc Windows Server Version 1803 vulnerabilities
568 known vulnerabilities affecting msrc/windows_server_version_1803.
Total CVEs
568
CISA KEV
22
actively exploited
Public exploits
44
Exploited in wild
25
Severity breakdown
CRITICAL12HIGH376MEDIUM174LOW6
Vulnerabilities
Page 27 of 29
CVE-2018-8313HIGHCVSS 7.82018-07-10
CVE-2018-8313 [HIGH] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions. An attacker who successfully exploited the vulnerability could impersonate processes, interject cross-process communication, or interrupt system functionality.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
T
msrc
CVE-2018-8282HIGHCVSS 8.82018-07-10
CVE-2018-8282 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnera
msrc
CVE-2018-8308MEDIUMCVSS 6.62018-07-10
CVE-2018-8308 [MEDIUM] Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerabilit
msrc
CVE-2018-8307MEDIUMCVSS 5.32018-07-10
CVE-2018-8307 [MEDIUM] WordPad Security Feature Bypass Vulnerability
WordPad Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists when Microsoft WordPad improperly handles embedded OLE objects. An attacker who successfully exploited the vulnerability could bypass content blocking.
In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability, and then convince a user to open the d
msrc
CVE-2018-8222MEDIUMCVSS 5.32018-07-10
CVE-2018-8222 [MEDIUM] Device Guard Code Integrity Policy Security Feature Bypass Vulnerability
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploited this vulnerability could inject code into a trusted PowerShell process to bypass the Device Guard Code Integrity policy on the
msrc
CVE-2018-8309MEDIUMCVSS 5.52018-07-10
CVE-2018-8309 [MEDIUM] Windows Denial of Service Vulnerability
Windows Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to execute co
msrc
CVE-2018-8210HIGHCVSS 7.32018-06-12
CVE-2018-8210 [HIGH] Windows Remote Code Execution Vulnerability
Windows Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited this vulnerability could take control of an affected system.
To exploit the vulnerability, an attacker would first have to log on to the target system and then run a specially crafted application.
The updates address the vulnerability by corr
msrc
CVE-2018-8213HIGHCVSS 7.82018-06-12
CVE-2018-8213 [HIGH] Windows Remote Code Execution Vulnerability
Windows Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited this vulnerability could take control of an affected system.
To exploit the vulnerability, an attacker would first have to log on to the target system and then run a specially crafted application.
The updates address the vulnerability by corr
msrc
CVE-2018-8208HIGHCVSS 7.0PoC2018-06-12
CVE-2018-8208 [HIGH] Windows Desktop Bridge Elevation of Privilege Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry.
An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To e
msrc
CVE-2018-8219HIGHCVSS 7.62018-06-12
CVE-2018-8219 [HIGH] Hypervisor Code Integrity Elevation of Privilege Vulnerability
Hypervisor Code Integrity Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows Hyper-V instruction emulation fails to properly enforce privilege levels. An attacker who successfully exploited this vulnerability could gain elevated privileges on a target guest operating system. The host operating system is not vulnerable to this attack.
This vulnerability b
msrc
CVE-2018-8231HIGHCVSS 8.12018-06-12
CVE-2018-8231 [HIGH] HTTP Protocol Stack Remote Code Execution Vulnerability
HTTP Protocol Stack Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code and take control of the affected system.
To exploit the vulnerability, in most situations, an unauthenticated attacker could send a specially craft
msrc
CVE-2018-1036HIGHCVSS 7.02018-06-12
CVE-2018-1036 [HIGH] NTFS Elevation of Privilege Vulnerability
NTFS Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.
The security update addre
msrc
CVE-2018-8169HIGHCVSS 7.02018-06-12
CVE-2018-8169 [HIGH] HIDParser Elevation of Privilege Vulnerability
HIDParser Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted applica
msrc
CVE-2018-8225HIGHCVSS 8.12018-06-12
CVE-2018-8225 [HIGH] Windows DNSAPI Remote Code Execution Vulnerability
Windows DNSAPI Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account.
To exploit the vulnerability, the attacker would use a malicious DNS server to send corrupted DNS
msrc
CVE-2018-8214HIGHCVSS 7.0PoC2018-06-12
CVE-2018-8214 [HIGH] Windows Desktop Bridge Elevation of Privilege Vulnerability
Windows Desktop Bridge Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry.
An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To e
msrc
CVE-2018-0982HIGHCVSS 7.0PoC2018-06-12
CVE-2018-0982 [HIGH] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions. An attacker who successfully exploited the vulnerability could impersonate processes, interject cross-process communication, or interrupt system functionality.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
T
msrc
CVE-2018-8233HIGHCVSS 7.82018-06-12
CVE-2018-8233 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an
msrc
CVE-2018-8221MEDIUMCVSS 5.32018-06-12
CVE-2018-8221 [MEDIUM] Device Guard Code Integrity Policy Security Feature Bypass Vulnerability
Device Guard Code Integrity Policy Security Feature Bypass Vulnerability
Description: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session. An attacker who successfully exploited this vulnerability could inject code into a trusted PowerShell process to bypass the Device Guard Code Integrity policy on the
msrc
CVE-2018-8121MEDIUMCVSS 4.72018-06-12
CVE-2018-8121 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addresses t
msrc
CVE-2018-8175MEDIUMCVSS 5.92018-06-12
CVE-2018-8175 [MEDIUM] WEBDAV Denial of Service Vulnerability
WEBDAV Denial of Service Vulnerability
Description: A denial of service vulnerability exists when Windows NT WEBDAV Minirdr attempts to query a WEBDAV directory. An attacker who successfully exploited the vulnerability could cause a denial of service.
To exploit the vulnerability, an attacker could host a specially crafted website and then convince a user to browse to it, which would cause the victim's system to stop responding. Howe
msrc