Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows Server 2008 R2 Service Pack 1.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-20936MEDIUM | Windows NDIS Information Disclosure VulnerabilityOut-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. CWE-125Jan 13, 2026 | CVSS4.3v3.1 | EPSS0.459% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20931HIGH | Windows Telephony Service Elevation of Privilege VulnerabilityExternal control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. CWE-73Jan 13, 2026 | CVSS8.0v3.1 | EPSS0.786% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20929HIGH | Windows HTTP.sys Elevation of Privilege VulnerabilityImproper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network. CWE-284Jan 13, 2026 | CVSS7.5v3.1 | EPSS1.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20872MEDIUM | NTLM Hash Disclosure Spoofing VulnerabilityExternal control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. CWE-73Jan 13, 2026 | CVSS6.5v3.1 | EPSS19.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20868HIGH | Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. CWE-122Jan 13, 2026 | CVSS8.8v3.1 | EPSS1.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20849HIGH | Windows Kerberos Elevation of Privilege VulnerabilityReliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network. CWE-807Jan 13, 2026 | CVSS7.5v3.1 | EPSS1.01% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20843HIGH | Windows Routing and Remote Access Service (RRAS) Elevation of Privilege VulnerabilityImproper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. CWE-284Jan 13, 2026 | CVSS7.8v3.1 | EPSS3.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20940HIGH | Windows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. CWE-822Jan 13, 2026 | CVSS7.8v3.1 | EPSS0.471% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20927MEDIUM | Windows SMB Server Denial of Service VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network. CWE-362Jan 13, 2026 | CVSS5.3v3.1 | EPSS0.927% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20925MEDIUM | NTLM Hash Disclosure Spoofing VulnerabilityExternal control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. CWE-73Jan 13, 2026 | CVSS6.5v3.1 | EPSS17.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20922HIGH | Windows NTFS Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. CWE-122Jan 13, 2026 | CVSS7.8v3.1 | EPSS1.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20921HIGH | Windows SMB Server Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. CWE-362Jan 13, 2026 | CVSS7.5v3.1 | EPSS1.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20875HIGH | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service VulnerabilityNull pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. CWE-476Jan 13, 2026 | CVSS7.5v3.1 | EPSS1.59% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20869HIGH | Windows Local Session Manager (LSM) Elevation of Privilege VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally. CWE-362Jan 13, 2026 | CVSS7.0v3.1 | EPSS0.299% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20860HIGH | Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityAccess of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. CWE-843Jan 13, 2026 | CVSS7.8v3.1 | EPSS8.29% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20847MEDIUM | Microsoft Windows File Explorer Spoofing VulnerabilityExposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. CWE-200Jan 13, 2026 | CVSS6.5v3.1 | EPSS1.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20840HIGH | Windows NTFS Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. CWE-122Jan 13, 2026 | CVSS7.8v3.1 | EPSS4.59% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20839MEDIUM | Windows Client-Side Caching (CSC) Service Information Disclosure VulnerabilityImproper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. CWE-284Jan 13, 2026 | CVSS5.5v3.1 | EPSS0.481% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20834MEDIUM | Windows Spoofing VulnerabilityAbsolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | CVSS4.6v3.1 | EPSS0.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20833MEDIUM | Windows Kerberos Information Disclosure VulnerabilityUse of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally. CWE-327Jan 13, 2026 | CVSS5.5v3.1 | EPSS0.501% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20831HIGH | Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityTime-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. CWE-367Jan 13, 2026 | CVSS7.8v3.1 | EPSS0.306% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20828MEDIUM | Windows rndismp6.sys Information Disclosure VulnerabilityOut-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. CWE-125Jan 13, 2026 | CVSS4.6v3.1 | EPSS0.644% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20821MEDIUM | Remote Procedure Call Information Disclosure VulnerabilityExposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. CWE-200Jan 13, 2026 | CVSS6.2v3.1 | EPSS0.719% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20820HIGH | Windows Common Log File System Driver Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. CWE-122Jan 13, 2026 | CVSS7.8v3.1 | EPSS2.57% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-20816HIGH | Windows Installer Elevation of Privilege VulnerabilityTime-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally. CWE-367Jan 13, 2026 | CVSS7.8v3.1 | EPSS2.49% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |