Vulnerabilities > Microsoft > Windows Server 2016 > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-09 CVE-2019-0732 Incorrect Authorization vulnerability in Microsoft products
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.
local
low complexity
microsoft CWE-863
4.6
2019-04-09 CVE-2019-0731 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-264
4.6
2019-04-09 CVE-2019-0730 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'.
local
low complexity
microsoft CWE-264
4.6
2019-04-09 CVE-2019-0688 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-327
5.0
2019-04-09 CVE-2019-0821 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'.
network
low complexity
microsoft
4.0
2019-04-09 CVE-2019-0774 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
network
microsoft
4.3
2019-04-09 CVE-2019-0761 Incorrect Authorization vulnerability in Microsoft Internet Explorer 10/11
A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs, aka 'Internet Explorer Security Feature Bypass Vulnerability'.
network
microsoft CWE-863
4.3
2019-04-09 CVE-2019-0754 Unspecified vulnerability in Microsoft products
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
local
low complexity
microsoft
4.9
2019-04-09 CVE-2019-0746 Unspecified vulnerability in Microsoft Chakracore, Edge and Internet Explorer
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.
network
microsoft
4.3
2019-04-09 CVE-2019-0704 Unspecified vulnerability in Microsoft products
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'.
network
low complexity
microsoft
4.0