Msrc Windows Server Version 2004 vulnerabilities

499 known vulnerabilities affecting msrc/windows_server_version_2004.

Total CVEs
499
CISA KEV
15
actively exploited
Public exploits
6
Exploited in wild
15
Severity breakdown
CRITICAL15HIGH346MEDIUM137LOW1

Vulnerabilities

Page 22 of 25
CVE-2020-1375HIGHCVSS 7.82020-07-14
CVE-2020-1375 [HIGH] Windows COM Server Elevation of Privilege Vulnerability Windows COM Server Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application t
msrc
CVE-2020-1370HIGHCVSS 7.82020-07-14
CVE-2020-1370 [HIGH] Windows Runtime Elevation of Privilege Vulnerability Windows Runtime Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnera
msrc
CVE-2020-1393HIGHCVSS 7.82020-07-14
CVE-2020-1393 [HIGH] Windows Diagnostics Hub Elevation of Privilege Vulnerability Windows Diagnostics Hub Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install progra
msrc
CVE-2020-1392HIGHCVSS 7.82020-07-14
CVE-2020-1392 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Delivery Optimization service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit
msrc
CVE-2020-1388HIGHCVSS 7.02020-07-14
CVE-2020-1388 [HIGH] Windows Elevation of Privilege Vulnerability Windows Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability by ensuring t
msrc
CVE-2020-1366HIGHCVSS 7.02020-07-14
CVE-2020-1366 [HIGH] Windows Print Workflow Service Elevation of Privilege Vulnerability Windows Print Workflow Service Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Print Workflow Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain elevated privileges and break out of the AppContainer sandbox. To exploit this vulnerability, an attacker would first have to log on to
msrc
CVE-2020-1423HIGHCVSS 7.82020-07-14
CVE-2020-1423 [HIGH] Windows Subsystem for Linux Elevation of Privilege Vulnerability Windows Subsystem for Linux Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files. An attacker who successfully exploited the vulnerability could execute code with elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a
msrc
CVE-2020-1362HIGHCVSS 7.82020-07-14
CVE-2020-1362 [HIGH] Windows WalletService Elevation of Privilege Vulnerability Windows WalletService Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update ad
msrc
CVE-2020-1372HIGHCVSS 7.82020-07-14
CVE-2020-1372 [HIGH] Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory. An attacker who successfully exploited this vulnerability could bypass access restrictions to delete files. To exploit this vulnerability, an attacker would fir
msrc
CVE-2020-1414HIGHCVSS 7.82020-07-14
CVE-2020-1414 [HIGH] Windows Runtime Elevation of Privilege Vulnerability Windows Runtime Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnera
msrc
CVE-2020-1404HIGHCVSS 7.82020-07-14
CVE-2020-1404 [HIGH] Windows Runtime Elevation of Privilege Vulnerability Windows Runtime Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnera
msrc
CVE-2020-1463HIGHCVSS 7.82020-07-14
CVE-2020-1463 [HIGH] Windows SharedStream Library Elevation of Privilege Vulnerability Windows SharedStream Library Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists in the way that the SharedStream Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The secur
msrc
CVE-2020-1431HIGHCVSS 7.12020-07-14
CVE-2020-1431 [HIGH] Windows AppX Deployment Extensions Elevation of Privilege Vulnerability Windows AppX Deployment Extensions Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update a
msrc
CVE-2020-1356HIGHCVSS 7.82020-07-14
CVE-2020-1356 [HIGH] Windows iSCSI Target Service Elevation of Privilege Vulnerability Windows iSCSI Target Service Elevation of Privilege Vulnerability Description: An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a
msrc
CVE-2020-1391MEDIUMCVSS 5.52020-07-14
CVE-2020-1391 [MEDIUM] Windows Agent Activation Runtime Information Disclosure Vulnerability Windows Agent Activation Runtime Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would first hav
msrc
CVE-2020-1330MEDIUMCVSS 5.52020-07-14
CVE-2020-1330 [MEDIUM] Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files. To exploit this vulnerability, an attacker would first have
msrc
CVE-2020-1361MEDIUMCVSS 5.52020-07-14
CVE-2020-1361 [MEDIUM] Windows WalletService Information Disclosure Vulnerability Windows WalletService Information Disclosure Vulnerability Description: An information disclosure vulnerability exists in the way that the WalletService handles memory. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a specially crafted application. The security update addresses the vulnerability by correcting how the WalletService handles me
msrc
CVE-2020-1386MEDIUMCVSS 5.52020-07-14
CVE-2020-1386 [MEDIUM] Connected User Experiences and Telemetry Service Information Disclosure Vulnerability Connected User Experiences and Telemetry Service Information Disclosure Vulnerability Description: An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information. Successful exploitation of the vulnerability could allow the attacker to read any file on the file system. To exploit the vulnerability, an attacker would
msrc
CVE-2020-1367MEDIUMCVSS 5.52020-07-14
CVE-2020-1367 [MEDIUM] Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses th
msrc
CVE-2020-1358MEDIUMCVSS 5.52020-07-14
CVE-2020-1358 [MEDIUM] Windows Resource Policy Information Disclosure Vulnerability Windows Resource Policy Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to disclose information about the victim system’s memory layout.
msrc
Msrc Windows Server Version 2004 vulnerabilities | cvebase