Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-1706 | Hig | 0.48 | 7.3 | 0.02 | Jan 12, 2021 | Windows LUAFV Elevation of Privilege Vulnerability | ||
| CVE-2021-1704 | Hig | 0.48 | 7.3 | 0.01 | Jan 12, 2021 | Windows Hyper-V Elevation of Privilege Vulnerability | ||
| CVE-2021-1685 | Hig | 0.48 | 7.3 | 0.01 | Jan 12, 2021 | Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | ||
| CVE-2020-17103 | Hig | 0.48 | 7.0 | 0.27 | Dec 10, 2020 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2020-1471 | Hig | 0.48 | 7.3 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails to check COM objects. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. To exploit the vulnerability, an attacker… | ||
| CVE-2020-1319 | Hig | 0.48 | 7.3 | 0.05 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change,… | ||
| CVE-2020-1557 | Hig | 0.48 | 7.3 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by… | ||
| CVE-2019-1439 | Med | 0.48 | 6.5 | 0.76 | Nov 12, 2019 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. | ||
| CVE-2019-1317 | Hig | 0.48 | 7.3 | 0.01 | Oct 10, 2019 | A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'. | ||
| CVE-2019-0856 | Hig | 0.48 | 7.2 | 0.18 | Apr 9, 2019 | A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'. | ||
| CVE-2026-32149 | Hig | 0.47 | 7.3 | 0.00 | Apr 14, 2026 | Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | ||
| CVE-2026-21247 | Hig | 0.47 | 7.3 | 0.01 | Feb 10, 2026 | Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. | ||
| CVE-2025-62565 | Hig | 0.47 | 7.3 | 0.01 | Dec 9, 2025 | Use after free in Windows Shell allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-25004 | Hig | 0.47 | 7.3 | 0.00 | Oct 14, 2025 | Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55236 | Hig | 0.47 | 7.3 | 0.00 | Sep 9, 2025 | Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally. | ||
| CVE-2025-54911 | Hig | 0.47 | 7.3 | 0.01 | Sep 9, 2025 | Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54116 | Hig | 0.47 | 7.3 | 0.01 | Sep 9, 2025 | Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-50161 | Hig | 0.47 | 7.3 | 0.01 | Aug 12, 2025 | Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-50159 | Hig | 0.47 | 7.3 | 0.01 | Aug 12, 2025 | Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-50154 | Med | 0.47 | 6.5 | 0.26 | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. |
- risk 0.48cvss 7.3epss 0.02
Windows LUAFV Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
Windows Hyper-V Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
- risk 0.48cvss 7.0epss 0.27
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails to check COM objects. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. To exploit the vulnerability, an attacker…
- risk 0.48cvss 7.3epss 0.05
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change,…
- risk 0.48cvss 7.3epss 0.04
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by…
- risk 0.48cvss 6.5epss 0.76
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
- risk 0.48cvss 7.3epss 0.01
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
- risk 0.48cvss 7.2epss 0.18
A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
- risk 0.47cvss 7.3epss 0.00
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
- risk 0.47cvss 7.3epss 0.01
Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.
- risk 0.47cvss 7.3epss 0.01
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.00
Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.
- risk 0.47cvss 7.3epss 0.01
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.01
Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.01
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 7.3epss 0.01
Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally.
- risk 0.47cvss 6.5epss 0.26
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
Page 150 of 248