VendorsMicrosoftwindows_server_2016all versions
Vulnerabilities

Microsoft Windows Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6183CVEs
CVE-2018-8450
A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-11-14 · Modified
9.0EPSS 0.161
CVE-2020-17049
Kerberos KDC Security Feature Bypass Vulnerability
Published 2020-11-11 · Modified
9.0EPSS 0.138
CVE-2020-0662
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
9.0EPSS 0.133
CVE-2019-0633
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0630.
Published 2019-03-06 · Modified
9.0EPSS 0.130
CVE-2020-1040
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
Published 2020-07-14 · Analyzed
9.0KEVEPSS 0.074
CVE-2020-1036
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
Published 2020-07-14 · Modified
9.0EPSS 0.062
CVE-2020-1042
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1043.
Published 2020-07-14 · Modified
9.0EPSS 0.060
CVE-2020-1032
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
Published 2020-07-14 · Modified
9.0EPSS 0.059
CVE-2020-1043
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1040, CVE-2020-1041, CVE-2020-1042.
Published 2020-07-14 · Modified
9.0EPSS 0.059
CVE-2020-1041
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1040, CVE-2020-1042, CVE-2020-1043.
Published 2020-07-14 · Modified
9.0EPSS 0.059
CVE-2019-0722
Windows Hyper-V Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.0EPSS 0.047
CVE-2020-1317
An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.
Published 2020-06-09 · Modified
9.0EPSS 0.044
CVE-2022-26826
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.040
CVE-2022-26815
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.038
CVE-2022-26813
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.038
CVE-2022-26812
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.038
CVE-2022-24536
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.038
CVE-2021-1701
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2021-1700
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2021-1667
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2022-26825
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.036
CVE-2022-26811
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.036
CVE-2022-26823
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.035
CVE-2022-26824
Windows DNS Server Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.035
CVE-2019-0938
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
Published 2019-05-16 · Modified
9.0EPSS 0.034
CVE-2022-23284
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-03-09 · Modified
9.0EPSS 0.032
CVE-2022-29129
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-29131
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-29128
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.0EPSS 0.028
CVE-2022-21920
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.028
CVE-2022-21922
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.028
CVE-2020-1067
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.0EPSS 0.025
CVE-2022-21857
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.025
CVE-2021-1706
Windows LUAFV Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.021
CVE-2017-0021
Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Structure Vulnerability." This vulnerability is different from that described in CVE-2017-0095.
Published 2017-03-17 · Modified
9.0EPSS 0.017
CVE-2021-26443
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Published 2021-11-10 · Modified
9.0EPSS 0.017
CVE-2021-40461
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
9.0EPSS 0.014
CVE-2024-38124
Windows Netlogon Elevation of Privilege Vulnerability
Published 2024-10-08 · Analyzed
9.0EPSS 0.012
CVE-2022-21901
Windows Hyper-V Elevation of Privilege Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.009
CVE-2021-40444
Microsoft MSHTML Remote Code Execution Vulnerability
Published 2021-09-15 · Analyzed
8.8KEVEPSS 0.975
← Prev13 / 155Next →