Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows Server, version 1903 (Server Core installation).
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-17162HIGH | Microsoft Windows Security Feature Bypass VulnerabilityMicrosoft Windows Security Feature Bypass Vulnerability Feb 25, 2021 | CVSS8.8v3.1 | EPSS2.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17140HIGH | Windows SMB Information Disclosure Vulnerability, aka 'Windows SMB Information Disclosure Vulnerability'. CWE-200Dec 9, 2020 | CVSS8.1v3.1 | EPSS12.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17139HIGH | Windows Overlay Filter Security Feature Bypass Vulnerability, aka 'Windows Overlay Filter Security Feature Bypass Vulnerability'. Dec 9, 2020 | CVSS7.8v3.1 | EPSS0.916% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17136HIGH | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-17103, CVE-2020-17134. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS14% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17134HIGH | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability, aka 'Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-17103, CVE-2020-17136. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17096HIGH | Windows NTFS Remote Code Execution Vulnerability, aka 'Windows NTFS Remote Code Execution Vulnerability'. Dec 9, 2020 | CVSS7.5v3.1 | EPSS18.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17098MEDIUM | Windows GDI+ Information Disclosure Vulnerability, aka 'Windows GDI+ Information Disclosure Vulnerability'. Dec 9, 2020 | CVSS5.5v3.1 | EPSS1.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Windows Digital Media Receiver Elevation of Privilege Vulnerability, aka 'Windows Digital Media Receiver Elevation of Privilege Vulnerability'. CWE-269Dec 9, 2020 | CVSS3.3v3.1 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2020-17095HIGH | Windows Hyper-V Remote Code Execution Vulnerability, aka 'Hyper-V Remote Code Execution Vulnerability'. Dec 9, 2020 | CVSS8.5v3.1 | EPSS4.66% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17094MEDIUM | Windows Error Reporting Information Disclosure Vulnerability, aka 'Windows Error Reporting Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-17138. Dec 9, 2020 | CVSS5.5v3.1 | EPSS1.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17092HIGH | Windows Network Connections Service Elevation of Privilege Vulnerability, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16996MEDIUM | Kerberos Security Feature Bypass Vulnerability, aka 'Kerberos Security Feature Bypass Vulnerability'. Dec 9, 2020 | CVSS6.5v3.1 | EPSS2.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16964HIGH | Windows Backup Engine Elevation of Privilege Vulnerability, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16958, CVE-2020-16959, CVE-2020-16960, CVE-2020-16961, CVE-2020-16962, CVE-2020-16963. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16961HIGH | Windows Backup Engine Elevation of Privilege Vulnerability, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16958, CVE-2020-16959, CVE-2020-16960, CVE-2020-16962, CVE-2020-16963, CVE-2020-16964. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16963HIGH | Windows Backup Engine Elevation of Privilege Vulnerability, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16958, CVE-2020-16959, CVE-2020-16960, CVE-2020-16961, CVE-2020-16962, CVE-2020-16964. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16962HIGH | Windows Backup Engine Elevation of Privilege Vulnerability, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16958, CVE-2020-16959, CVE-2020-16960, CVE-2020-16961, CVE-2020-16963, CVE-2020-16964. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16959HIGH | Windows Backup Engine Elevation of Privilege Vulnerability, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16958, CVE-2020-16960, CVE-2020-16961, CVE-2020-16962, CVE-2020-16963, CVE-2020-16964. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16960HIGH | Windows Backup Engine Elevation of Privilege Vulnerability, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16958, CVE-2020-16959, CVE-2020-16961, CVE-2020-16962, CVE-2020-16963, CVE-2020-16964. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-16958HIGH | Windows Backup Engine Elevation of Privilege Vulnerability, aka 'Windows Backup Engine Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16959, CVE-2020-16960, CVE-2020-16961, CVE-2020-16962, CVE-2020-16963, CVE-2020-16964. CWE-269Dec 9, 2020 | CVSS7.8v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-1599MEDIUM | Windows Spoofing VulnerabilityWindows Spoofing Vulnerability Nov 11, 2020 | CVSS5.5v3.1 | EPSS19.1% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2020-17088HIGH | Windows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Common Log File System Driver Elevation of Privilege Vulnerability CWE-269Nov 11, 2020 | CVSS7.8v3.1 | EPSS0.879% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17090MEDIUM | Microsoft Defender for Endpoint Security Feature Bypass VulnerabilityMicrosoft Defender for Endpoint Security Feature Bypass Vulnerability Nov 11, 2020 | CVSS5.3v3.1 | EPSS3.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17087HIGH | Windows Kernel Local Elevation of Privilege VulnerabilityWindows Kernel Local Elevation of Privilege Vulnerability | CVSS7.8v3.1 | EPSS5.43% | PoCs6 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17076HIGH | Windows Update Orchestrator Service Elevation of Privilege VulnerabilityWindows Update Orchestrator Service Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2020-17073, CVE-2020-17074. CWE-269Nov 11, 2020 | CVSS7.8v3.1 | EPSS0.889% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-17077HIGH | Windows Update Stack Elevation of Privilege VulnerabilityWindows Update Stack Elevation of Privilege Vulnerability CWE-269Nov 11, 2020 | CVSS7.8v3.1 | EPSS0.963% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |