Vulnerabilities > Microsoft > Windows Server 2019 > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-07-15 CVE-2019-1074 Link Following vulnerability in Microsoft products
An elevation of privilege vulnerability exists in Microsoft Windows where certain folders, with local service privilege, are vulnerable to symbolic link attack.
local
low complexity
microsoft CWE-59
5.5
2019-07-15 CVE-2019-1073 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
5.5
2019-07-15 CVE-2019-1071 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
5.5
2019-07-15 CVE-2019-0975 Unspecified vulnerability in Microsoft Windows Server 2016 and Windows Server 2019
A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses.
network
low complexity
microsoft
6.3
2019-07-15 CVE-2019-0966 Improper Input Validation vulnerability in Microsoft products
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.
low complexity
microsoft CWE-20
6.8
2019-06-12 CVE-2019-1050 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-200
6.5
2019-06-12 CVE-2019-1046 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-200
5.5
2019-06-12 CVE-2019-1043 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.
network
low complexity
microsoft
6.8
2019-06-12 CVE-2019-1040 Unspecified vulnerability in Microsoft products
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
network
high complexity
microsoft
5.9
2019-06-12 CVE-2019-1039 Improper Initialization vulnerability in Microsoft products
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulnerability'.
local
low complexity
microsoft CWE-665
5.5