Vulnerabilities > Microsoft > Windows Server > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-08-15 CVE-2018-8350 Unspecified vulnerability in Microsoft Windows 10 and Windows Server
A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, aka "Windows PDF Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
network
microsoft
critical
9.3
2018-08-15 CVE-2018-8414 Improper Input Validation vulnerability in Microsoft Windows 10 and Windows Server
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.
network
microsoft CWE-20
critical
9.3
2012-09-18 CVE-2012-4969 Unspecified vulnerability in Microsoft Internet Explorer
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
network
microsoft
critical
9.3
2009-06-10 CVE-2009-0230 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
network
low complexity
microsoft CWE-264
critical
9.0
2009-06-10 CVE-2009-0568 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
network
low complexity
microsoft CWE-264
critical
10.0