Skip to content
VulniPulse

Microsoft Server Security Advisories & CVEs

1727 advisories tracked · Microsoft Security Update Guide (MSRC) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor MS Server CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your MS Server device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in MS Server's recent advisories.

Official source

Microsoft Security Update Guide (MSRC)

Polled via the official MSRC Security Update Guide RSS feed (api.msrc.microsoft.com, no credentials required), scoped to SERVER products only — Windows Server, Exchange, SQL Server, SharePoint, Hyper-V and companion server roles. Client-only CVEs (Edge, Office apps, consumer Windows) are filtered out via the monthly CVRF document's affected-product list.

Latest MS Server advisories

UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1129 +1] Windows Server: elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. Affected products named by the advisory: Windows Server; Windows Server, version 1903 (Server Core installation).

CVE-2019-1129CVE-2019-1130
Windows Server
Jul 29, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2019-1068] Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR): remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. Affected products named by the advisory: Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR); Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR); Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR); Microsoft SQL Server 2017 for x64-based Systems (GDR); and 5 more. Affected products named by the advisory: Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR); Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU); Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR); and 1 more.

CVE-2019-1068
SQL Server
Jul 15, 2019
High7.8MS Server Exploited CISA KEV

High [CVE-2019-1069] Task Scheduler Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations. Affected products named by the advisory: Windows Server, version 1803 (Server Core Installation); Windows Server 2019; Windows Server 2019 (Server Core installation); Windows Server, version 1903 (Server Core installation); and 4 more. Affected products named by the advisory: Windows Server 2016 (Server Core installation); windows_server_2016.

CVE-2019-1069
Windows Server
Jun 12, 2019
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2018-8453] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2018-8453
Windows Server
Oct 10, 2018
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2018-8174] remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CVE-2018-8174
Windows Server
May 9, 2018
UnratedMS Server Exploited CISA KEV

Advisory [CVE-2018-8120 +3] elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.

CVE-2018-8120CVE-2018-8124CVE-2018-8164+1
Windows Server
May 9, 2018
Medium5.5MS Server Exploited CISA KEV

Medium [CVE-2013-3900] WinVerifyTrust Signature Validation Vulnerability

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verification behavior as a default functionality on supported releases of Microsoft Windows. This behavior remains available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013. The supporting code for this reg key was incorporated at the time of release for Windows 10 and Windows 11, so no security update is required; however, the reg key must be set. See the Security Updates table for the list of affected software. Vulnerability Description A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for portable executable (PE) files.

CVE-2013-3900
Windows Server
Dec 11, 2013

← All vendors