Home/Product/microsoft windows server 20h2
Product

microsoft windows server 20h2

52 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-35759
all versions
Windows Local Security Authority (LSA) Denial of Service Vulnerability
6.5MEDIUM
CVE-2022-35758
all versions
Windows Kernel Memory Information Disclosure Vulnerability
5.5MEDIUM
CVE-2022-35757
all versions
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
7.3HIGH
CVE-2022-35756
all versions
Windows Kerberos Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-35755
all versions
Windows Print Spooler Elevation of Privilege Vulnerability
7.3HIGH
CVE-2022-35754
all versions
Unified Write Filter Elevation of Privilege Vulnerability
6.7MEDIUM
CVE-2022-35753
all versions
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
8.1HIGH
CVE-2022-35752
all versions
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
8.1HIGH
CVE-2022-35751
< 10.0.19042.1889
Windows Hyper-V Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-35750
all versions
Win32k Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-35749
all versions
Windows Digital Media Receiver Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-35748
all versions
HTTP.sys Denial of Service Vulnerability
7.5HIGH
CVE-2022-35747
all versions
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
5.9MEDIUM
CVE-2022-35746
all versions
Windows Digital Media Receiver Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-35745
all versions
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
8.1HIGH
CVE-2022-35744
all versions
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
9.8CRITICAL
CVE-2022-35743
all versions
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
7.8HIGH
CVE-2022-34713
< 10.0.19042.1889
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
7.8HIGH
CVE-2022-22047
< 10.0.19042.1826
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-30190
< 10.0.19042.1766
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. A
7.8HIGH
CVE-2022-26925
< 10.0.19042.1706
Windows LSA Spoofing Vulnerability
8.1HIGH
CVE-2022-26904
< 10.0.19042.1645
Windows User Profile Service Elevation of Privilege Vulnerability
7.0HIGH
CVE-2022-24521
< 10.0.19042.1645
Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-22718
< 10.0.19042.1526
Windows Print Spooler Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-21999
< 10.0.19042.1526
Windows Print Spooler Elevation of Privilege Vulnerability
7.8HIGH
CVE-2022-21971
< 10.0.19042.1526
Windows Runtime Remote Code Execution Vulnerability
7.8HIGH
CVE-2022-21919
< 10.0.19042.1466
Windows User Profile Service Elevation of Privilege Vulnerability
7.0HIGH
CVE-2022-21882
< 10.0.19042.1466
Win32k Elevation of Privilege Vulnerability
7.0HIGH
CVE-2021-43226
< 10.0.19042.1415
Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-42278
< 10.0.19042.1348
Active Directory Domain Services Elevation of Privilege Vulnerability
7.5HIGH
CVE-2021-41379
< 10.0.19042.1348
Windows Installer Elevation of Privilege Vulnerability
5.5MEDIUM
CVE-2021-41357
< 10.0.19042.1288
Win32k Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-40450
< 10.0.19042.1288
Win32k Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-40449
< 10.0.19042.1288
Win32k Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-40444
< 10.0.19042.1237
<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft
8.8HIGH
CVE-2021-36955
< 10.0.19042.1237
Windows Common Log File System Driver Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-36948
< 10.0.19042.1165
Windows Update Medic Service Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-36942
< 10.0.19042.1165
Windows LSA Spoofing Vulnerability
7.5HIGH
CVE-2021-34486
< 10.0.19042.1165
Windows Event Tracing Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-34484
< 10.0.19042.1165
Windows User Profile Service Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-33771
< 10.0.19042.1110
Windows Kernel Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-31979
< 10.0.19042.1110
Windows Kernel Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-34527
< 10.0.19042.1083
<p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operati
8.8HIGH
CVE-2021-33739
< 10.0.19042.1052
Microsoft DWM Core Library Elevation of Privilege Vulnerability
8.4HIGH
CVE-2021-31956
< 10.0.19042.1052
Windows NTFS Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-31955
< 10.0.19042.1052
Windows Kernel Information Disclosure Vulnerability
5.5MEDIUM
CVE-2021-31201
< 10.0.19042.1052
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
5.2MEDIUM
CVE-2021-31199
< 10.0.19042.1052
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
5.2MEDIUM
CVE-2021-31166
< 10.0.19042.982
HTTP Protocol Stack Remote Code Execution Vulnerability
9.8CRITICAL
CVE-2021-28310
all versions
Win32k Elevation of Privilege Vulnerability
7.8HIGH
CVE-2021-1732
all versions
Windows Win32k Elevation of Privilege Vulnerability
7.8HIGH
CVE-2020-1472
all versions
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a d
5.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin