VendorsMicrosoftwindows_server_20161903
Vulnerabilities

Microsoft Windows Server 1903

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1018CVEs
CVE-2020-1372
An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles objects in memory, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1405.
Published 2020-07-14 · Modified
7.8EPSS 0.007
CVE-2020-1385
An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles objects in memory, aka 'Windows Credential Picker Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
7.8EPSS 0.007
CVE-2019-1235
An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server process does not validate the source of input or commands it receives, aka 'Windows Text Service Framework Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
7.8EPSS 0.006
CVE-2020-1152
Windows Win32k Elevation of Privilege Vulnerability
Published 2020-09-11 · Modified
7.8EPSS 0.006
CVE-2020-16997
Remote Desktop Protocol Server Information Disclosure Vulnerability
Published 2020-11-11 · Modified
7.7EPSS 0.040
CVE-2019-0965
Windows Hyper-V Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
7.7EPSS 0.013
CVE-2020-0681
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0734.
Published 2020-02-11 · Modified
7.6EPSS 0.106
CVE-2020-0908
Windows Text Service Module Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
7.6EPSS 0.033
CVE-2020-16896
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2020-10-16 · Modified
7.5EPSS 0.126
CVE-2019-1225
Remote Desktop Protocol Server Information Disclosure Vulnerability
Published 2019-08-14 · Modified
7.5EPSS 0.105
CVE-2020-1206
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Information Disclosure Vulnerability'.
Published 2020-06-09 · Modified
7.5EPSS 0.105
CVE-2019-1453
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
Published 2019-12-10 · Modified
7.5EPSS 0.099
CVE-2020-1374
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
7.5EPSS 0.091
CVE-2019-1224
Remote Desktop Protocol Server Information Disclosure Vulnerability
Published 2019-08-14 · Modified
7.5EPSS 0.084
CVE-2019-1083
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.078
CVE-2020-0611
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
Published 2020-01-14 · Modified
7.5EPSS 0.067
CVE-2019-1006
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.060
CVE-2020-0876
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
Published 2020-03-12 · Modified
7.5EPSS 0.059
CVE-2019-0820
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Published 2019-05-16 · Modified
7.5EPSS 0.057
CVE-2020-0660
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
Published 2020-02-11 · Modified
7.5EPSS 0.054
CVE-2019-1206
Windows DHCP Server Denial of Service Vulnerability
Published 2019-08-14 · Modified
7.5EPSS 0.053
CVE-2020-1031
Windows DHCP Server Information Disclosure Vulnerability
Published 2020-09-11 · Modified
7.5EPSS 0.051
CVE-2019-1223
Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability
Published 2019-08-14 · Modified
7.5EPSS 0.051
CVE-2020-0836
Windows DNS Denial of Service Vulnerability
Published 2020-09-11 · Modified
7.5EPSS 0.051
CVE-2019-0980
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
Published 2019-05-16 · Modified
7.5EPSS 0.049
CVE-2019-0981
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
Published 2019-05-16 · Modified
7.5EPSS 0.049
CVE-2020-0909
A denial of service vulnerability exists when Hyper-V on a Windows Server fails to properly handle specially crafted network packets.To exploit the vulnerability, an attacker would send specially crafted network packets to the Hyper-V Server.The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to properly handle these network packets., aka 'Windows Hyper-V Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
7.5EPSS 0.046
CVE-2019-0811
A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Windows DNS Server Denial of Service Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.045
CVE-2019-0865
A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures., aka 'SymCrypt Denial of Service Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.045
CVE-2020-1228
Windows DNS Denial of Service Vulnerability
Published 2020-09-11 · Modified
7.5EPSS 0.045
CVE-2019-1255
A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.
Published 2019-09-23 · Modified
7.5EPSS 0.041
CVE-2020-0645
A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'.
Published 2020-03-12 · Modified
7.5EPSS 0.039
CVE-2019-0941
Microsoft IIS Server Denial of Service Vulnerability
Published 2019-06-12 · Modified
7.5EPSS 0.030
CVE-2020-16949
Microsoft Outlook Denial of Service Vulnerability
Published 2020-10-16 · Modified
7.5EPSS 0.030
CVE-2019-1198
Microsoft Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.5EPSS 0.019
CVE-2020-0917
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0918.
Published 2020-04-15 · Modified
7.4EPSS 0.016
CVE-2020-0918
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0917.
Published 2020-04-15 · Modified
7.4EPSS 0.013
CVE-2019-1317
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
Published 2019-10-10 · Modified
7.3EPSS 0.010
CVE-2019-1184
Windows Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.21 PoCEPSS 0.702
CVE-2020-0951
Windows Defender Application Control Security Feature Bypass Vulnerability
Published 2020-09-11 · Modified
7.2EPSS 0.070
← Prev19 / 26Next →