Microsoft Server Security Advisories & CVEs
472 advisories tracked · Microsoft Security Update Guide (MSRC) · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor MS Server CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your MS Server device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in MS Server's recent advisories.
Official source
Microsoft Security Update Guide (MSRC)
Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.
Latest MS Server advisories
Medium [CVE-2021-34491] Win32k Information Disclosure Vulnerability
Win32k Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); Windows Server 2016; Windows Server 2016 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2.
Medium [CVE-2021-33783] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.
Medium [CVE-2021-33782] Windows Authenticode Spoofing Vulnerability
Windows Authenticode Spoofing Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.
Medium [CVE-2021-33765] Windows Installer Spoofing Vulnerability
Windows Installer Spoofing Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.
Medium [CVE-2021-33764] Windows Key Distribution Center Information Disclosure Vulnerability
Windows Key Distribution Center Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.
Medium [CVE-2021-33763] Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 6 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2.
Medium [CVE-2021-33760] Media Foundation Information Disclosure Vulnerability
Media Foundation Information Disclosure Vulnerability Affected products named by the advisory: Windows Server version 2004; Windows Server version 20H2; Windows Server, version 1909 (Server Core installation).
Medium [CVE-2021-33757] Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability
Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.
Medium [CVE-2021-33755] Windows Hyper-V Denial of Service Vulnerability
Windows Hyper-V Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2.
Medium [CVE-2021-33744] Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Windows Secure Kernel Mode Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2.
Medium [CVE-2021-31961] Windows InstallService Elevation of Privilege Vulnerability
Windows InstallService Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2.
Medium [CVE-2021-27052] Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019.
Medium [CVE-2021-26892] Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability Affected products named by the advisory: Windows Server 2016; Windows Server 2016 (Server Core installation); Windows Server 2019; Windows Server 2019 (Server Core installation); and 3 more. Affected products named by the advisory: Windows Server version 2004; Windows Server version 20H2; Windows Server, version 1909 (Server Core installation).
Medium [CVE-2021-26886] User Profile Service Denial of Service Vulnerability
User Profile Service Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 7 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2; and 1 more.
Medium [CVE-2021-26884] Windows Media Photo Codec Information Disclosure Vulnerability
Windows Media Photo Codec Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2012; Windows Server 2012 (Server Core installation); Windows Server 2012 R2; Windows Server 2012 R2 (Server Core installation); and 7 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server version 2004; Windows Server version 20H2; and 1 more.
Medium [CVE-2021-26869] Windows ActiveX Installer Service Information Disclosure Vulnerability
Windows ActiveX Installer Service Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2012; Windows Server 2012 (Server Core installation); and 9 more. Affected products named by the advisory: Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server version 2004; and 2 more.
Medium [CVE-2021-24107] Windows Event Tracing Information Disclosure Vulnerability
Windows Event Tracing Information Disclosure Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 11 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 3 more.
Medium [CVE-2021-24104] Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Foundation 2013 Service Pack 1; Microsoft SharePoint Server 2019.
Medium [CVE-2021-26854] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2013 Cumulative Update 23; Microsoft Exchange Server 2016 Cumulative Update 18; Microsoft Exchange Server 2016 Cumulative Update 19; Microsoft Exchange Server 2019 Cumulative Update 7; and 1 more. Affected products named by the advisory: Microsoft Exchange Server 2019 Cumulative Update 8.
Medium [CVE-2020-1145] Windows GDI Information Disclosure Vulnerability
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how GDI handles memory addresses. Affected products named by the advisory: Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).