Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23253 | Med | 0.47 | 6.5 | 0.56 | Mar 9, 2022 | Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | ||
| CVE-2021-40469 | Hig | 0.47 | 7.2 | 0.08 | Oct 13, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-34480 | Med | 0.47 | 6.8 | 0.40 | Aug 12, 2021 | Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2021-28325 | Med | 0.47 | 6.5 | 0.62 | Apr 13, 2021 | Windows SMB Information Disclosure Vulnerability | ||
| CVE-2019-1252 | Med | 0.47 | 6.5 | 0.61 | Sep 11, 2019 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286. | ||
| CVE-2026-70307 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-65678 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62908 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62892 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62774 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62773 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62753 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62748 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62734 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62729 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62728 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62726 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62725 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62724 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-62723 | Hig | 0.46 | 7.0 | 0.00 | Aug 11, 2026 | Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally. |
- risk 0.47cvss 6.5epss 0.56
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
- risk 0.47cvss 7.2epss 0.08
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.47cvss 6.8epss 0.40
Scripting Engine Memory Corruption Vulnerability
- risk 0.47cvss 6.5epss 0.62
Windows SMB Information Disclosure Vulnerability
- risk 0.47cvss 6.5epss 0.61
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.0epss 0.00
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Page 153 of 248