VendorsMicrosoftwindows_server_20161909
Vulnerabilities

Microsoft Windows Server 1909

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

965CVEs
CVE-2020-0646
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
Published 2020-01-14 · Analyzed
10.0KEV1 PoCEPSS 0.992
CVE-2021-26897
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.116
CVE-2020-17051
Windows Network File System Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
10.0EPSS 0.106
CVE-2021-26894
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.073
CVE-2021-26895
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
10.0EPSS 0.073
CVE-2020-0690
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
10.0EPSS 0.070
CVE-2020-1467
Windows Hard Link Elevation of Privilege Vulnerability
Published 2020-08-17 · Modified
10.0EPSS 0.035
CVE-2021-28476
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
9.9EPSS 0.386
CVE-2020-17095
Windows Hyper-V Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
9.9EPSS 0.050
CVE-2021-26867
Windows Hyper-V Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.9EPSS 0.028
CVE-2021-24074
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.257
CVE-2021-24094
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.221
CVE-2021-26877
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.8EPSS 0.165
CVE-2021-24078
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.119
CVE-2021-26893
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.8EPSS 0.070
CVE-2020-17090
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Published 2020-11-11 · Modified
9.8EPSS 0.033
CVE-2021-1694
Windows Update Stack Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
9.8EPSS 0.032
CVE-2021-24077
Windows Fax Service Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.029
CVE-2020-17040
Windows Hyper-V Security Feature Bypass Vulnerability
Published 2020-11-11 · Modified
9.8EPSS 0.027
CVE-2021-27092
Azure AD Web Sign-in Security Feature Bypass Vulnerability
Published 2021-04-13 · Modified
9.8EPSS 0.026
CVE-2021-1722
Windows Fax Service Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.024
CVE-2020-1421
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
9.3EPSS 0.745
CVE-2020-1074
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.484
CVE-2020-1400
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407.
Published 2020-07-14 · Modified
9.3EPSS 0.237
CVE-2020-0883
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0881.
Published 2020-03-12 · Modified
9.3EPSS 0.220
CVE-2020-0687
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
Published 2020-04-15 · Modified
9.3EPSS 0.193
CVE-2020-0995
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0889, CVE-2020-0953, CVE-2020-0959, CVE-2020-0960, CVE-2020-0988, CVE-2020-0992, CVE-2020-0994, CVE-2020-0999, CVE-2020-1008.
Published 2020-04-15 · Modified
9.3EPSS 0.177
CVE-2020-0606
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0605.
Published 2020-01-14 · Modified
9.3EPSS 0.172
CVE-2020-0964
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
Published 2020-04-15 · Modified
9.3EPSS 0.171
CVE-2020-0881
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0883.
Published 2020-03-12 · Modified
9.3EPSS 0.168
CVE-2019-1468
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
Published 2019-12-10 · Modified
9.3EPSS 0.166
CVE-2020-0734
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0681.
Published 2020-02-11 · Modified
9.3EPSS 0.165
CVE-2020-1208
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1236.
Published 2020-06-09 · Modified
9.3EPSS 0.147
CVE-2020-1299
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
9.3EPSS 0.145
CVE-2020-1412
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
9.3EPSS 0.140
CVE-2020-1248
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
9.3EPSS 0.137
CVE-2020-1435
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
9.3EPSS 0.137
CVE-2020-1401
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1407.
Published 2020-07-14 · Modified
9.3EPSS 0.131
CVE-2020-0988
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0889, CVE-2020-0953, CVE-2020-0959, CVE-2020-0960, CVE-2020-0992, CVE-2020-0994, CVE-2020-0995, CVE-2020-0999, CVE-2020-1008.
Published 2020-04-15 · Modified
9.3EPSS 0.120
CVE-2020-0999
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0889, CVE-2020-0953, CVE-2020-0959, CVE-2020-0960, CVE-2020-0988, CVE-2020-0992, CVE-2020-0994, CVE-2020-0995, CVE-2020-1008.
Published 2020-04-15 · Modified
9.3EPSS 0.120
1 / 25Next →