VendorsMicrosoftwindows_server_2016any version
Vulnerabilities

Microsoft Windows Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5823CVEs
CVE-2020-1471
Windows CloudExperienceHost Elevation of Privilege Vulnerability
Published 2020-09-11 · Modified
7.8EPSS 0.012
CVE-2020-1207
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1247, CVE-2020-1251, CVE-2020-1253, CVE-2020-1310.
Published 2020-06-09 · Modified
7.8EPSS 0.012
CVE-2018-8343
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8342.
Published 2018-08-15 · Modified
7.8EPSS 0.012
CVE-2018-8471
An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handles objects in memory, aka "Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 8.1, Windows 7, Windows Server 2019.
Published 2018-11-14 · Modified
7.8EPSS 0.012
CVE-2018-8485
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8554, CVE-2018-8561.
Published 2018-11-14 · Modified
7.8EPSS 0.012
CVE-2018-8561
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8485, CVE-2018-8554.
Published 2018-11-14 · Modified
7.8EPSS 0.012
CVE-2018-8462
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
Published 2018-09-13 · Modified
7.8EPSS 0.012
CVE-2018-8415
A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-11-14 · Modified
7.8EPSS 0.012
CVE-2023-24897
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Published 2023-06-14 · Modified
7.8EPSS 0.012
CVE-2025-24061
Windows Mark of the Web Security Feature Bypass Vulnerability
Published 2025-03-11 · Analyzed
7.8EPSS 0.012
CVE-2019-1267
An elevation of privilege vulnerability exists in Microsoft Compatibility Appraiser where a configuration file, with local privileges, is vulnerable to symbolic link and hard link attacks, aka 'Microsoft Compatibility Appraiser Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
7.8EPSS 0.012
CVE-2019-1082
An elevation of privilege vulnerability exists in Microsoft Windows where a certain DLL, with Local Service privilege, is vulnerable to race planting a customized DLL.An attacker who successfully exploited this vulnerability could potentially elevate privilege to SYSTEM.The update addresses this vulnerability by requiring SYSTEM privileges for a certain DLL., aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1074.
Published 2019-07-15 · Modified
7.8EPSS 0.012
CVE-2018-8484
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory, aka "DirectX Graphics Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Published 2018-10-10 · Modified
7.8EPSS 0.012
CVE-2019-1342
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1315, CVE-2019-1339.
Published 2019-10-10 · Modified
7.8EPSS 0.012
CVE-2024-38184
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Published 2024-08-13 · Modified
7.8EPSS 0.012
CVE-2017-11782
The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Elevation of Privilege Vulnerability".
Published 2017-10-13 · Modified
7.8EPSS 0.012
CVE-2018-0756
The Windows kernel in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Kernel Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0742, CVE-2018-0809, CVE-2018-0820 and CVE-2018-0843.
Published 2018-02-15 · Modified
7.8EPSS 0.012
CVE-2022-41089
.NET Framework Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
7.8EPSS 0.012
CVE-2021-26862
Windows Installer Elevation of Privilege Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.012
CVE-2023-35356
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-07-11 · Modified
7.8EPSS 0.012
CVE-2022-30164
Kerberos AppContainer Security Feature Bypass Vulnerability
Published 2022-06-15 · Modified
7.8EPSS 0.012
CVE-2020-1475
Windows Server Resource Management Service Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
7.8EPSS 0.012
CVE-2023-21808
.NET and Visual Studio Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
7.8EPSS 0.011
CVE-2021-36963
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2021-09-15 · Modified
7.8EPSS 0.011
CVE-2021-26873
Windows User Profile Service Elevation of Privilege Vulnerability
Published 2021-03-11 · Modified
7.8EPSS 0.011
CVE-2020-16958
Windows Backup Engine Elevation of Privilege Vulnerability
Published 2020-12-09 · Modified
7.8EPSS 0.011
CVE-2020-16959
Windows Backup Engine Elevation of Privilege Vulnerability
Published 2020-12-09 · Modified
7.8EPSS 0.011
CVE-2020-16962
Windows Backup Engine Elevation of Privilege Vulnerability
Published 2020-12-09 · Modified
7.8EPSS 0.011
CVE-2020-16963
Windows Backup Engine Elevation of Privilege Vulnerability
Published 2020-12-09 · Modified
7.8EPSS 0.011
CVE-2020-16964
Windows Backup Engine Elevation of Privilege Vulnerability
Published 2020-12-09 · Modified
7.8EPSS 0.011
CVE-2020-1070
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1048.
Published 2020-05-21 · Modified
7.8EPSS 0.011
CVE-2022-38004
Windows Fax Service Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
7.8EPSS 0.011
CVE-2022-41057
Windows HTTP.sys Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.011
CVE-2017-0102
Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 let attackers with access to targets systems gain privileges when Windows fails to properly validate buffer lengths, aka "Windows Elevation of Privilege Vulnerability."
Published 2017-03-17 · Modified
7.8EPSS 0.011
CVE-2020-1470
Windows Work Folders Service Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
7.8EPSS 0.011
CVE-2025-59254
Microsoft DWM Core Library Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.81 PoCEPSS 0.011
CVE-2024-30086
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Published 2024-06-11 · Modified
7.8EPSS 0.011
CVE-2024-38051
Windows Graphics Component Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
7.8EPSS 0.011
CVE-2020-0791
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898.
Published 2020-03-12 · Modified
7.8EPSS 0.011
CVE-2018-8641
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8639.
Published 2018-12-12 · Modified
7.8EPSS 0.011
← Prev44 / 146Next →