Vulnerabilities > Microsoft > Windows Server 2016 > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-04-15 CVE-2020-0952 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
network
microsoft CWE-200
4.3
2020-04-15 CVE-2020-0947 Information Exposure vulnerability in Microsoft Windows 10 and Windows Server 2016
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
network
microsoft CWE-200
4.3
2020-04-15 CVE-2020-0946 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
network
microsoft CWE-200
4.3
2020-04-15 CVE-2020-0945 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
network
microsoft CWE-200
4.3
2020-04-15 CVE-2020-0944 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-04-15 CVE-2020-0939 Information Exposure vulnerability in Microsoft Windows 10 and Windows Server 2016
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
network
microsoft CWE-200
4.3
2020-04-15 CVE-2020-0938 Improper Input Validation vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'.
network
microsoft CWE-20
6.8
2020-04-15 CVE-2020-0937 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
network
microsoft CWE-200
4.3
2020-04-15 CVE-2020-0934 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows WpcDesktopMonSvc improperly manages memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-04-15 CVE-2020-0794 Improper Input Validation vulnerability in Microsoft products
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
local
low complexity
microsoft CWE-20
4.9