Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55234 | Hig | 0.59 | 8.8 | 0.20 | Sep 9, 2025 | SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for… | ||
| CVE-2025-54918 | Hig | 0.59 | 8.8 | 0.19 | Sep 9, 2025 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-38124 | Cri | 0.59 | 9.0 | 0.01 | Oct 8, 2024 | Windows Netlogon Elevation of Privilege Vulnerability | ||
| CVE-2024-20674 | Hig | 0.59 | 8.8 | 0.17 | Jan 9, 2024 | Windows Kerberos Security Feature Bypass Vulnerability | ||
| CVE-2023-36017 | Hig | 0.59 | 8.8 | 0.25 | Nov 14, 2023 | Windows Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2023-29325 | Hig | 0.59 | 8.1 | 0.84 | May 9, 2023 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2022-44698 | Med | 0.59 | 5.4 | 0.76 | KEV | Dec 13, 2022 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2022-21972 | Hig | 0.59 | 8.1 | 0.80 | May 10, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-23285 | Hig | 0.59 | 8.8 | 0.26 | Mar 9, 2022 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2022-21990 | Hig | 0.59 | 8.8 | 0.19 | Mar 9, 2022 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2022-21901 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2021-26443 | Cri | 0.59 | 9.0 | 0.02 | Nov 10, 2021 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability | ||
| CVE-2021-34535 | Hig | 0.59 | 8.8 | 0.20 | Aug 12, 2021 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2021-34448 | Med | 0.59 | 6.8 | 0.40 | KEV | Jul 16, 2021 | Scripting Engine Memory Corruption Vulnerability | |
| CVE-2020-1436 | Hig | 0.59 | 8.8 | 0.21 | Jul 14, 2020 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code… | ||
| CVE-2020-0964 | Hig | 0.59 | 8.8 | 0.17 | Apr 15, 2020 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | ||
| CVE-2020-0687 | Hig | 0.59 | 8.8 | 0.19 | Apr 15, 2020 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. | ||
| CVE-2020-0883 | Hig | 0.59 | 8.8 | 0.22 | Mar 12, 2020 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0881. | ||
| CVE-2020-0881 | Hig | 0.59 | 8.8 | 0.17 | Mar 12, 2020 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0883. | ||
| CVE-2019-1468 | Hig | 0.59 | 8.8 | 0.17 | Dec 10, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'. |
- risk 0.59cvss 8.8epss 0.20
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for…
- risk 0.59cvss 8.8epss 0.19
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- risk 0.59cvss 9.0epss 0.01
Windows Netlogon Elevation of Privilege Vulnerability
- risk 0.59cvss 8.8epss 0.17
Windows Kerberos Security Feature Bypass Vulnerability
- risk 0.59cvss 8.8epss 0.25
Windows Scripting Engine Memory Corruption Vulnerability
- risk 0.59cvss 8.1epss 0.84
Windows OLE Remote Code Execution Vulnerability
- risk 0.59cvss 5.4epss 0.76
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.59cvss 8.1epss 0.80
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.26
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.19
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.59cvss 9.0epss 0.02
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
- risk 0.59cvss 8.8epss 0.20
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.59cvss 6.8epss 0.40
Scripting Engine Memory Corruption Vulnerability
- risk 0.59cvss 8.8epss 0.21
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code…
- risk 0.59cvss 8.8epss 0.17
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
- risk 0.59cvss 8.8epss 0.19
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
- risk 0.59cvss 8.8epss 0.22
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0881.
- risk 0.59cvss 8.8epss 0.17
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0883.
- risk 0.59cvss 8.8epss 0.17
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
Page 14 of 248