windows_server_2025_server_core_installation vulnerabilities
CVEs whose affected-version data names the windows_server_2025_server_core_installation package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
781 CVEsRSS
CVE-2026-50386High· 7.8Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50380Critical· 9.6Windows GDI+ Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2026-50370High· 8.8DHCP Server Service Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-50363High· 7.8Windows Push Notifications Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVE-2026-50360High· 8.8Windows SMB Server Elevation of Privilege Vulnerability
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-50343High· 7.8PoCMicrosoft Install Service Elevation of Privilege Vulnerability
Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.
CVE-2026-50341Medium· 5.5Windows NTFS Information Disclosure Vulnerability
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-50337High· 7.8Windows Notification Elevation of Privilege Vulnerability
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.
CVE-2026-50331High· 7.8Windows Application Model Core API Elevation of Privilege Vulnerability
Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.
CVE-2026-50329High· 7.8Microsoft DWM Core Library Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50328High· 7.5Windows Server Update Service (WSUS) Tampering Vulnerability
Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
CVE-2026-50327High· 7.8Windows Media Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.
CVE-2026-50326High· 7.8Windows Unified Consent System Elevation of Privilege Vulnerability
Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.
CVE-2026-50313High· 7.8Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50309High· 7.8Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50307High· 7.0Windows TCP/IP Elevation of Privilege Vulnerability
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-50306High· 7.8Windows TCP/IP Elevation of Privilege Vulnerability
Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-50434Medium· 5.5Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50430Medium· 5.5Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50425High· 7.8Windows Internal System User Profile Elevation of Privilege Vulnerability
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
CVE-2026-50396High· 7.0Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
CVE-2026-50390High· 7.0Windows Kernel Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50377Medium· 5.5Windows Kernel Elevation of Privilege Vulnerability
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50357High· 7.8Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVE-2026-50348High· 7.0Windows Runtime Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50347High· 7.8Windows Data.dll Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
CVE-2026-50345High· 7.0Windows Runtime Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
CVE-2026-50339Medium· 5.5Windows Push Notification Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
CVE-2026-50335High· 7.8Windows Operating Systems Elevation of Privilege Vulnerability
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
CVE-2026-50330High· 7.5Windows Remote Desktop Client Elevation of Privilege Vulnerability
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.