Msrc Windows Server Version 1903 vulnerabilities

587 known vulnerabilities affecting msrc/windows_server_version_1903.

Total CVEs
587
CISA KEV
14
actively exploited
Public exploits
26
Exploited in wild
16
Severity breakdown
CRITICAL10HIGH437MEDIUM138LOW2

Vulnerabilities

Page 24 of 30
CVE-2019-1437HIGHCVSS 7.02019-11-12
CVE-2019-1437 [HIGH] Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. In a local attack scenario, an attacker could exploit this vulnerability by running a specially crafted applicatio
msrc
CVE-2019-1430HIGHCVSS 7.32019-11-12
CVE-2019-1430 [HIGH] Microsoft Windows Media Foundation Remote Code Execution Vulnerability Microsoft Windows Media Foundation Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when Windows Media Foundation improperly parses specially crafted QuickTime media files. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system coul
msrc
CVE-2019-1436MEDIUMCVSS 5.52019-11-12
CVE-2019-1436 [MEDIUM] Win32k Information Disclosure Vulnerability Win32k Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security
msrc
CVE-2019-1381MEDIUMCVSS 6.62019-11-12
CVE-2019-1381 [MEDIUM] Microsoft Windows Information Disclosure Vulnerability Microsoft Windows Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations. An attacker who successfully exploited the vulnerability could potentially access unauthorized files. To exploit this vulnerability, an authenticated attacker could run a specially crafted application in user mode. The update a
msrc
CVE-2018-12207MEDIUMCVSS 4.72019-11-12
CVE-2018-12207 [MEDIUM] Windows Denial of Service Vulnerability Windows Denial of Service Vulnerability Description: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to execute c
msrc
CVE-2019-1374MEDIUMCVSS 5.52019-11-12
CVE-2019-1374 [MEDIUM] Windows Error Reporting Elevation of Privilege Vulnerability Windows Error Reporting Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system function
msrc
CVE-2019-1324MEDIUMCVSS 5.32019-11-12
CVE-2019-1324 [MEDIUM] Windows TCP/IP Information Disclosure Vulnerability Windows TCP/IP Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to send specially crafted IPv6 packets to a remote
msrc
CVE-2019-1399MEDIUMCVSS 5.42019-11-12
CVE-2019-1399 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability Description: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host ma
msrc
CVE-2019-1310MEDIUMCVSS 5.82019-11-12
CVE-2019-1310 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability Description: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest o
msrc
CVE-2019-0712MEDIUMCVSS 5.82019-11-12
CVE-2019-0712 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability Description: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest o
msrc
CVE-2019-1440MEDIUMCVSS 5.02019-11-12
CVE-2019-1440 [MEDIUM] Win32k Information Disclosure Vulnerability Win32k Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security
msrc
CVE-2019-1309MEDIUMCVSS 5.82019-11-12
CVE-2019-1309 [MEDIUM] Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability Description: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest o
msrc
CVE-2019-1365HIGHCVSS 7.52019-10-08
CVE-2019-1365 [CRITICAL] Microsoft IIS Server Elevation of Privilege Vulnerability Microsoft IIS Server Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it. An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox. The security updat
msrc
CVE-2019-1336HIGHCVSS 7.02019-10-08
CVE-2019-1336 [HIGH] Microsoft Windows Update Client Elevation of Privilege Vulnerability Microsoft Windows Update Client Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerab
msrc
CVE-2019-1323HIGHCVSS 7.02019-10-08
CVE-2019-1323 [HIGH] Microsoft Windows Update Client Elevation of Privilege Vulnerability Microsoft Windows Update Client Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerab
msrc
CVE-2019-1322HIGHCVSS 7.0KEVPoC2019-10-08
CVE-2019-1322 [HIGH] Microsoft Windows Elevation of Privilege Vulnerability Microsoft Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability
msrc
CVE-2019-1316HIGHCVSS 7.32019-10-08
CVE-2019-1316 [HIGH] Microsoft Windows Setup Elevation of Privilege Vulnerability Microsoft Windows Setup Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly handle privileges. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would fir
msrc
CVE-2019-1311HIGHCVSS 7.82019-10-08
CVE-2019-1311 [HIGH] Windows Imaging API Remote Code Execution Vulnerability Windows Imaging API Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. To exploit the vulnerability, an attacker would have to convince a user to open a specially crafted .WIM f
msrc
CVE-2019-1340HIGHCVSS 7.82019-10-08
CVE-2019-1340 [HIGH] Microsoft Windows Elevation of Privilege Vulnerability Microsoft Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The
msrc
CVE-2019-1320HIGHCVSS 7.02019-10-08
CVE-2019-1320 [HIGH] Microsoft Windows Elevation of Privilege Vulnerability Microsoft Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability
msrc