Msrc Windows Server Version 1903 vulnerabilities

587 known vulnerabilities affecting msrc/windows_server_version_1903.

Total CVEs
587
CISA KEV
14
actively exploited
Public exploits
26
Exploited in wild
16
Severity breakdown
CRITICAL10HIGH437MEDIUM138LOW2

Vulnerabilities

Page 30 of 30
CVE-2019-0931HIGHCVSS 7.02019-05-14
CVE-2019-0931 [HIGH] Windows Storage Service Elevation of Privilege Vulnerability Windows Storage Service Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker would first have to gain execution on the victim system, then run a specially craf
msrc
CVE-2019-0892HIGHCVSS 7.82019-05-14
CVE-2019-0892 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an
msrc
CVE-2019-0707HIGHCVSS 7.02019-05-14
CVE-2019-0707 [HIGH] Windows NDIS Elevation of Privilege Vulnerability Windows NDIS Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it. To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level. An attacker who successfull
msrc
CVE-2019-0725HIGHCVSS 8.12019-05-14
CVE-2019-0725 [CRITICAL] Windows DHCP Server Remote Code Execution Vulnerability Windows DHCP Server Remote Code Execution Vulnerability Description: A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could run arbitrary code on the DHCP server. To exploit the vulnerability, a remote unauthenticated attacker could send a specially crafted packet to an affected DHCP server
msrc
CVE-2019-0886MEDIUMCVSS 5.52019-05-14
CVE-2019-0886 [MEDIUM] Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker on a guest operating system could run a specially crafted application that could cause the Hyper-V host operating system to disclos
msrc
CVE-2019-0733MEDIUMCVSS 5.32019-05-14
CVE-2019-0733 [MEDIUM] Windows Defender Application Control Security Feature Bypass Vulnerability Windows Defender Application Control Security Feature Bypass Vulnerability Description: A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could circumvent Windows PowerShell Constrained Language Mode on the machine. To exploit the vulnerabil
msrc
CVE-2019-0727MEDIUMCVSS 6.72019-05-14
CVE-2019-0727 [HIGH] Diagnostic Hub Standard Collector, Visual Studio Standard Collector Elevation of Privilege Vulnerability Diagnostic Hub Standard Collector, Visual Studio Standard Collector Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the sys
msrc