Vulnerabilities > Microsoft > Windows Server 2016 > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-11 CVE-2020-0666 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-02-11 CVE-2020-0665 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
network
microsoft CWE-269
6.8
2020-02-11 CVE-2020-0661 Improper Input Validation vulnerability in Microsoft products
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
low complexity
microsoft CWE-20
5.5
2020-02-11 CVE-2020-0660 Improper Input Validation vulnerability in Microsoft products
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
network
low complexity
microsoft CWE-20
5.0
2020-02-11 CVE-2020-0659 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-02-11 CVE-2020-0657 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-02-07 CVE-2019-13163 Inadequate Encryption Strength vulnerability in Fujitsu products
The Fujitsu TLS library allows a man-in-the-middle attack.
4.3
2020-01-14 CVE-2020-0638 Improper Privilege Management vulnerability in Microsoft products
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6
2020-01-14 CVE-2020-0637 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-200
4.0
2020-01-14 CVE-2020-0636 Improper Privilege Management vulnerability in Microsoft Windows 10 and Windows Server 2016
An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-269
4.6