Vulnerabilities > Microsoft > Windows Server 2016 > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-03-12 CVE-2020-0770 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-03-12 CVE-2020-0769 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-03-12 CVE-2020-0763 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-03-12 CVE-2020-0762 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2016
An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-03-12 CVE-2020-0684 Improper Privilege Management vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
network
microsoft CWE-269
6.8
2020-03-12 CVE-2020-0645 Improper Input Validation vulnerability in Microsoft products
A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'.
network
low complexity
microsoft CWE-20
5.0
2020-02-11 CVE-2020-0754 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-02-11 CVE-2020-0753 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-02-11 CVE-2020-0752 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-02-11 CVE-2020-0750 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'Connected Devices Platform Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6