Msrc Windows Server Version 1903 vulnerabilities

587 known vulnerabilities affecting msrc/windows_server_version_1903.

Total CVEs
587
CISA KEV
14
actively exploited
Public exploits
26
Exploited in wild
16
Severity breakdown
CRITICAL10HIGH437MEDIUM138LOW2

Vulnerabilities

Page 25 of 30
CVE-2019-1345MEDIUMCVSS 5.5PoC2019-10-08
CVE-2019-1345 [MEDIUM] Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
msrc
CVE-2019-1337MEDIUMCVSS 5.5PoC2019-10-08
CVE-2019-1337 [MEDIUM] Windows Update Client Information Disclosure Vulnerability Windows Update Client Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could potentially disclose memory contents of an elevated process. To exploit this vulnerability, an authenticated attacker could run a specially crafted application in u
msrc
CVE-2019-1060MEDIUMCVSS 6.42019-10-08
CVE-2019-1060 [HIGH] MS XML Remote Code Execution Vulnerability MS XML Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the vulnerability, an attacker could host a specially crafted website designed to invoke MSXML through a web browser. Howe
msrc
CVE-2019-1321MEDIUMCVSS 5.82019-10-08
CVE-2019-1321 [HIGH] Microsoft Windows CloudStore Elevation of Privilege Vulnerability Microsoft Windows CloudStore Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL). An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log on to th
msrc
CVE-2019-1368MEDIUMCVSS 4.92019-10-08
CVE-2019-1368 [MEDIUM] Windows Secure Boot Security Feature Bypass Vulnerability Windows Secure Boot Security Feature Bypass Vulnerability Description: A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality. An attacker who successfully exploited this vulnerability could disclose protected kernel memory. To exploit the vulnerability, an attacker must gain physical access to the target system prior to the next system reboot. The security
msrc
CVE-2019-1343MEDIUMCVSS 6.5PoC2019-10-08
CVE-2019-1343 [MEDIUM] Windows Denial of Service Vulnerability Windows Denial of Service Vulnerability Description: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specific file on a network s
msrc
CVE-2019-1317MEDIUMCVSS 6.42019-10-08
CVE-2019-1317 [HIGH] Microsoft Windows Denial of Service Vulnerability Microsoft Windows Denial of Service Vulnerability Description: A denial of service vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would allow an attacker to ove
msrc
CVE-2019-1334MEDIUMCVSS 4.72019-10-08
CVE-2019-1334 [MEDIUM] Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
msrc
CVE-2019-1347MEDIUMCVSS 5.7PoC2019-10-08
CVE-2019-1347 [MEDIUM] Windows Denial of Service Vulnerability Windows Denial of Service Vulnerability Description: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specific file on a network s
msrc
CVE-2019-1232HIGHCVSS 7.82019-09-10
CVE-2019-1232 [HIGH] Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker with unprivileged access to a vulnerable system could e
msrc
CVE-2019-1253HIGHCVSS 7.8KEVPoC2019-09-10
CVE-2019-1253 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deplo
msrc
CVE-2019-1287HIGHCVSS 7.82019-09-10
CVE-2019-1287 [HIGH] Windows Network Connectivity Assistant Elevation of Privilege Vulnerability Windows Network Connectivity Assistant Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the way that the Windows Network Connectivity Assistant handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a sp
msrc
CVE-2019-1278HIGHCVSS 7.82019-09-10
CVE-2019-1278 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability by ensuring
msrc
CVE-2019-1277HIGHCVSS 7.82019-09-10
CVE-2019-1277 [HIGH] Windows Audio Service Elevation of Privilege Vulnerability Windows Audio Service Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows Audio Service when a malformed parameter is processed. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges when used in conjunction with another vulnerability. To exploit the vulnerability, an attacker could run a specially crafted ap
msrc
CVE-2019-1303HIGHCVSS 7.82019-09-10
CVE-2019-1303 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deplo
msrc
CVE-2019-1289HIGHCVSS 7.02019-09-10
CVE-2019-1289 [MEDIUM] Windows Update Delivery Optimization Elevation of Privilege Vulnerability Windows Update Delivery Optimization Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions. An attacker who successfully exploited the vulnerability could overwrite files that require higher privileges than what the attacker already has. To exploit this vulnerabil
msrc
CVE-2019-1267HIGHCVSS 7.32019-09-10
CVE-2019-1267 [HIGH] Microsoft Compatibility Appraiser Elevation of Privilege Vulnerability Microsoft Compatibility Appraiser Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install p
msrc
CVE-2019-1292HIGHCVSS 7.82019-09-10
CVE-2019-1292 [MEDIUM] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate permissions. To exploit this vulnerability, an attacker would first have to log on to the system. An att
msrc
CVE-2019-1273HIGHCVSS 8.22019-09-10
CVE-2019-1273 [MEDIUM] Active Directory Federation Services XSS Vulnerability Active Directory Federation Services XSS Vulnerability Description: A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error messages. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected ADFS server. The attacker who successfully exploited the vulnerability could then perform c
msrc
CVE-2019-1270MEDIUMCVSS 6.32019-09-10
CVE-2019-1270 [MEDIUM] Microsoft Windows Store Installer Elevation of Privilege Vulnerability Microsoft Windows Store Installer Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack. An attacker who successfully exploited this vulnerability could bypass access restrictions to add or remove files. To exploit this vulnerability, an attacker would first have to lo
msrc