VendorsMicrosoftwindows_serverall versions
Vulnerabilities

Microsoft Windows Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

303CVEs
CVE-2022-21907
HTTP Protocol Stack Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
10.01 PoCEPSS 0.928
CVE-2009-0568
The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
Published 2009-06-10 · Modified
10.0EPSS 0.324
CVE-2018-8421
A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0.
Published 2018-09-13 · Modified
10.0EPSS 0.291
CVE-2007-1917
Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
10.0EPSS 0.067
CVE-2007-1916
Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
10.0EPSS 0.067
CVE-2022-21898
DirectX Graphics Kernel Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
10.0EPSS 0.024
CVE-2022-21874
Windows Security Center API Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
10.0EPSS 0.023
CVE-2022-26937
Windows Network File System Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.760
CVE-2021-43217
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
9.8EPSS 0.064
CVE-2022-21849
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.8EPSS 0.062
CVE-2022-22012
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.040
CVE-2022-29130
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.038
CVE-2021-43215
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
Published 2021-12-15 · Modified
9.8EPSS 0.027
CVE-2022-21972
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.3EPSS 0.793
CVE-2022-23270
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.3EPSS 0.704
CVE-2018-8420
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-09-13 · Modified
9.3EPSS 0.489
CVE-2018-8284
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
9.3EPSS 0.415
CVE-2009-1133
Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
Published 2009-08-12 · Modified
9.3EPSS 0.305
CVE-2018-8332
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Published 2018-09-13 · Modified
9.3EPSS 0.191
CVE-2018-8350
A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
Published 2018-08-15 · Modified
9.3EPSS 0.186
CVE-2017-11827
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Microsoft browsers handle objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability".
Published 2017-11-15 · Modified
9.3EPSS 0.076
CVE-2022-21974
Roaming Security Rights Management Services Remote Code Execution Vulnerability
Published 2022-02-09 · Modified
9.3EPSS 0.050
CVE-2022-21851
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.028
CVE-2022-21850
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.028
CVE-2022-21878
Windows Geolocation Service Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.027
CVE-2022-21888
Windows Modern Execution Server Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.3EPSS 0.025
CVE-2022-21992
Windows Mobile Device Management Remote Code Execution Vulnerability
Published 2022-02-09 · Modified
9.3EPSS 0.025
CVE-2009-0230
The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
Published 2009-06-10 · Modified
9.0EPSS 0.349
CVE-2022-23284
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
9.0EPSS 0.032
CVE-2022-29129
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-29131
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-29128
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-21922
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.028
CVE-2022-21920
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.028
CVE-2022-21857
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.025
CVE-2021-40461
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
9.0EPSS 0.014
CVE-2022-21901
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.009
CVE-2022-23285
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-03-09 · Modified
8.8EPSS 0.256
CVE-2022-21990
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-03-09 · Modified
8.8EPSS 0.188
CVE-2018-8260
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
8.8EPSS 0.155
1 / 8Next →