VendorsMicrosoftwindows_serverall versions
Vulnerabilities

Microsoft Windows Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

303CVEs
CVE-2022-23291
Windows DWM Core Library Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.8EPSS 0.006
CVE-2022-22001
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Published 2022-02-09 · Modified
7.8EPSS 0.006
CVE-2022-24459
Windows Fax and Scan Service Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.8EPSS 0.006
CVE-2022-21833
Virtual Machine IDE Drive Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
7.8EPSS 0.006
CVE-2022-21834
Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
7.8EPSS 0.006
CVE-2021-43207
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.006
CVE-2022-24454
Windows Security Support Provider Interface Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.8EPSS 0.006
CVE-2022-23290
Windows Inking COM Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.8EPSS 0.006
CVE-2022-29103
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
7.8EPSS 0.006
CVE-2022-21910
Microsoft Cluster Port Driver Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
7.8EPSS 0.006
CVE-2022-21981
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2022-02-09 · Modified
7.8EPSS 0.006
CVE-2021-43230
Windows NTFS Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.006
CVE-2021-43240
NTFS Set Short Name Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.006
CVE-2021-42285
Windows Kernel Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2021-43239
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.005
CVE-2021-43223
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.005
CVE-2021-43248
Windows Digital Media Receiver Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.8EPSS 0.005
CVE-2021-42286
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.005
CVE-2022-29113
Windows Digital Media Receiver Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
7.8EPSS 0.004
CVE-2022-24537
Windows Hyper-V Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
7.8EPSS 0.004
CVE-2017-11873
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, and CVE-2017-11871.
Published 2017-11-15 · Modified
7.61 PoCEPSS 0.698
CVE-2017-11861
Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
Published 2017-11-15 · Modified
7.61 PoCEPSS 0.642
CVE-2017-11870
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11871, and CVE-2017-11873.
Published 2017-11-15 · Modified
7.61 PoCEPSS 0.596
CVE-2018-0825
StructuredQuery in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how objects are handled in memory, aka "StructuredQuery Remote Code Execution Vulnerability".
Published 2018-02-15 · Modified
7.6EPSS 0.165
CVE-2018-0883
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how file copy destinations are validated, aka "Windows Shell Remote Code Execution Vulnerability".
Published 2018-03-14 · Modified
7.6EPSS 0.145
CVE-2017-11869
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Microsoft browsers handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
Published 2017-11-15 · Modified
7.6EPSS 0.098
CVE-2017-11871
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, and CVE-2017-11873.
Published 2017-11-15 · Modified
7.6EPSS 0.080
CVE-2017-11862
ChakraCore and Microsoft Edge in Windows 10 1709 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11846, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
Published 2017-11-15 · Modified
7.6EPSS 0.079
CVE-2017-11856
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11855.
Published 2017-11-15 · Modified
7.6EPSS 0.056
CVE-2022-24460
Tablet Windows User Interface Application Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
7.6EPSS 0.020
CVE-2019-0545
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.
Published 2019-01-08 · Modified
7.5EPSS 0.096
CVE-2018-8360
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.
Published 2018-08-15 · Modified
7.5EPSS 0.090
CVE-2017-11788
Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remotely send specially crafted messages that could cause a denial of service against the system due to improperly handing objects in memory, aka "Windows Search Denial of Service Vulnerability".
Published 2017-11-15 · Modified
7.5EPSS 0.079
CVE-2021-43893
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.5EPSS 0.066
CVE-2021-36953
Windows TCP/IP Denial of Service Vulnerability
Published 2021-10-13 · Modified
7.5EPSS 0.050
CVE-2022-21883
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.044
CVE-2007-1915
Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Published 2007-04-10 · Modified
7.5EPSS 0.044
CVE-2022-21848
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.042
CVE-2021-42284
Windows Hyper-V Denial of Service Vulnerability
Published 2021-11-10 · Modified
7.5EPSS 0.037
CVE-2022-21904
Windows GDI Information Disclosure Vulnerability
Published 2022-01-11 · Modified
7.5EPSS 0.035
← Prev4 / 8Next →