Skip to content
VulniPulse

Microsoft Server Security Advisories & CVEs

1356 advisories tracked · Microsoft Security Update Guide (MSRC) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your MS Server device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in MS Server's recent advisories.

Official source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server advisories

UnratedMS Server

Unknown [CVE-2020-1099] Microsoft Office SharePoint XSS Vulnerability

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user. The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes web requests. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019.

CVE-2020-1099
SharePoint Server
May 21, 2020
UnratedMS Server

Unknown [CVE-2020-1100] Microsoft Office SharePoint XSS Vulnerability

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user. The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes web requests. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2013 Service Pack 1; Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2010 Service Pack 2; Microsoft SharePoint Server 2019.

CVE-2020-1100
SharePoint Server
May 21, 2020
UnratedMS Server

Unknown [CVE-2020-1069] Microsoft SharePoint Server Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page to perform actions in the security context of the SharePoint application pool process. To exploit the vulnerability, an authenticated user must create and invoke a specially crafted page on an affected version of Microsoft SharePoint Server. The security update addresses the vulnerability by correcting how Microsoft SharePoint Server handles processing of created content. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Foundation 2013 Service Pack 1; Microsoft SharePoint Server 2019.

CVE-2020-1069
SharePoint Server
May 21, 2020
UnratedMS Server

Unknown [CVE-2020-1023] Microsoft SharePoint Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint. The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Foundation 2013 Service Pack 1; Microsoft SharePoint Server 2019.

CVE-2020-1023
SharePoint Server
May 21, 2020
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2020-0796] Windows 10 Version 1903 for 32-bit Systems: remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'. Affected products named by the advisory: Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).

CVE-2020-0796
Windows Server
Mar 12, 2020
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2020-0787] elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1909 (Server Core installation); Windows Server, version 1903 (Server Core installation).

CVE-2020-0787
Windows Server
Mar 12, 2020
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2020-0618] remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU).

CVE-2020-0618
SQL Server
Feb 11, 2020
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2020-0638] Windows: elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Update Notification Manager Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation); Windows Server, version 1909 (Server Core installation).

CVE-2020-0638
Windows Server
Jan 14, 2020
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2019-1458] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. Affected product named by the advisory: Windows Server.

CVE-2019-1458
Windows Server
Dec 10, 2019
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2019-1405] elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1405
Windows Server
Nov 12, 2019
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2019-1385] elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1385
Windows Server
Nov 12, 2019
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2019-1129 +1] Windows Server: elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1129CVE-2019-1130
Windows Server
Jul 29, 2019
High7.8MS Server Exploited CISA KEV

High [CVE-2019-1069] Task Scheduler Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations. Affected products named by the advisory: Windows Server, version 1803 (Server Core Installation); Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server, version 1903 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); windows_server_2016.

CVE-2019-1069
Windows Server
Jun 12, 2019
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2018-8453] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2018-8453
Windows Server
Oct 10, 2018
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2018-8174] remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2018-8174
Windows Server
May 9, 2018
UnratedMS Server Exploited CISA KEV

Unknown [CVE-2018-8120 +3] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.

CVE-2018-8120CVE-2018-8124CVE-2018-8164+1
Windows Server
May 9, 2018

← All vendors