Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1019 | Hig | 0.59 | 8.5 | 0.14 | Jun 12, 2019 | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this… | ||
| CVE-2019-0902 | Hig | 0.59 | 8.8 | 0.19 | May 16, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893,… | ||
| CVE-2019-0853 | Hig | 0.59 | 8.8 | 0.28 | Apr 9, 2019 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | ||
| CVE-2019-0842 | Hig | 0.59 | 8.8 | 0.18 | Apr 9, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. | ||
| CVE-2019-0795 | Hig | 0.59 | 8.8 | 0.21 | Apr 9, 2019 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0793. | ||
| CVE-2019-0793 | Hig | 0.59 | 8.8 | 0.17 | Apr 9, 2019 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0795. | ||
| CVE-2019-0792 | Hig | 0.59 | 8.8 | 0.17 | Apr 9, 2019 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0793, CVE-2019-0795. | ||
| CVE-2019-0791 | Hig | 0.59 | 8.8 | 0.17 | Apr 9, 2019 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795. | ||
| CVE-2019-0630 | Hig | 0.59 | 8.8 | 0.17 | Mar 5, 2019 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0633. | ||
| CVE-2018-8582 | Hig | 0.59 | 8.8 | 0.19 | Nov 14, 2018 | A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique… | ||
| CVE-2018-8256 | Hig | 0.59 | 8.8 | 0.23 | Nov 14, 2018 | A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016,… | ||
| CVE-2018-8494 | Hig | 0.59 | 8.8 | 0.22 | Oct 10, 2018 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019,… | ||
| CVE-2026-68820 | Hig | 0.58 | 7.0 | 0.00 | KEV | Aug 11, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-54110 | Hig | 0.58 | 8.8 | 0.04 | Sep 9, 2025 | Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-53145 | Hig | 0.58 | 8.8 | 0.06 | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | ||
| CVE-2025-53144 | Hig | 0.58 | 8.8 | 0.06 | Aug 12, 2025 | Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network. | ||
| CVE-2025-49724 | Hig | 0.58 | 8.8 | 0.08 | Jul 8, 2025 | Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-29962 | Hig | 0.58 | 8.8 | 0.14 | May 13, 2025 | Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21391 | Hig | 0.58 | 7.1 | 0.02 | KEV | Feb 11, 2025 | Windows Storage Elevation of Privilege Vulnerability | |
| CVE-2024-43573 | Med | 0.58 | 6.5 | 0.44 | KEV | Oct 8, 2024 | Windows MSHTML Platform Spoofing Vulnerability |
- risk 0.59cvss 8.5epss 0.14
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this…
- risk 0.59cvss 8.8epss 0.19
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893,…
- risk 0.59cvss 8.8epss 0.28
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
- risk 0.59cvss 8.8epss 0.18
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.
- risk 0.59cvss 8.8epss 0.21
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0793.
- risk 0.59cvss 8.8epss 0.17
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0795.
- risk 0.59cvss 8.8epss 0.17
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0793, CVE-2019-0795.
- risk 0.59cvss 8.8epss 0.17
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.
- risk 0.59cvss 8.8epss 0.17
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0633.
- risk 0.59cvss 8.8epss 0.19
A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique…
- risk 0.59cvss 8.8epss 0.23
A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016,…
- risk 0.59cvss 8.8epss 0.22
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019,…
- risk 0.58cvss 7.0epss 0.00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.58cvss 8.8epss 0.04
Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.58cvss 8.8epss 0.06
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
- risk 0.58cvss 8.8epss 0.06
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
- risk 0.58cvss 8.8epss 0.08
Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.
- risk 0.58cvss 8.8epss 0.14
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
- risk 0.58cvss 7.1epss 0.02
Windows Storage Elevation of Privilege Vulnerability
- risk 0.58cvss 6.5epss 0.44
Windows MSHTML Platform Spoofing Vulnerability
Page 15 of 248