Vulnerabilities > Microsoft > Windows Server 2016 > High

DATE CVE VULNERABILITY TITLE RISK
2020-08-17 CVE-2020-1466 Unspecified vulnerability in Microsoft products
A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests.
local
low complexity
microsoft
7.8
2020-08-17 CVE-2020-1464 Improper Verification of Cryptographic Signature vulnerability in Microsoft products
A spoofing vulnerability exists when Windows incorrectly validates file signatures.
local
low complexity
microsoft CWE-347
7.8
2020-08-17 CVE-2020-1378 Out-of-bounds Write vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory.
network
high complexity
microsoft CWE-787
7.5
2020-08-17 CVE-2020-1377 Unspecified vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory.
local
low complexity
microsoft
7.8
2020-08-17 CVE-2020-1339 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects.
local
low complexity
microsoft
7.8
2020-08-17 CVE-2020-1337 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system.
local
low complexity
microsoft CWE-367
7.8
2020-07-14 CVE-2020-1429 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-07-14 CVE-2020-1424 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2
2020-07-14 CVE-2020-1418 Improper Input Validation vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Diagnostics Execution Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-20
7.2
2020-07-14 CVE-2020-1411 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
7.2