Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-28316 | Med | 0.27 | 4.2 | 0.01 | Apr 13, 2021 | Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability | ||
| CVE-2020-1566 | Med | 0.27 | 4.2 | 0.02 | Aug 17, 2020 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete… | ||
| CVE-2025-29839 | Med | 0.26 | 4.0 | 0.00 | May 13, 2025 | Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally. | ||
| CVE-2020-1033 | Med | 0.26 | 4.0 | 0.01 | Sep 11, 2020 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticated attacker could… | ||
| CVE-2026-45642 | Low | 0.25 | 3.9 | 0.00 | Jun 9, 2026 | Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack. | ||
| CVE-2025-49760 | Low | 0.23 | 3.5 | 0.01 | Jul 8, 2025 | External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2020-24588 | Low | 0.23 | 3.5 | 0.04 | May 11, 2021 | The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is… | ||
| CVE-2026-21249 | Low | 0.22 | 3.3 | 0.11 | Feb 10, 2026 | External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | ||
| CVE-2022-21977 | Low | 0.22 | 3.3 | 0.03 | Mar 9, 2022 | Media Foundation Information Disclosure Vulnerability | ||
| CVE-2021-28312 | Low | 0.22 | 3.3 | 0.07 | Apr 13, 2021 | Windows NTFS Denial of Service Vulnerability | ||
| CVE-2020-17097 | Low | 0.22 | 3.3 | 0.01 | Dec 10, 2020 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | ||
| CVE-2019-1488 | Low | 0.22 | 3.3 | 0.01 | Dec 10, 2019 | A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microsoft Defender Security Feature Bypass Vulnerability'. | ||
| CVE-2019-1418 | Low | 0.22 | 3.3 | 0.02 | Nov 12, 2019 | An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'. | ||
| CVE-2025-21337 | Low | 0.21 | 3.3 | 0.01 | Feb 11, 2025 | Windows NTFS Elevation of Privilege Vulnerability | ||
| CVE-2022-38022 | Low | 0.21 | 3.3 | 0.01 | Oct 11, 2022 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2018-8482 | Low | 0.21 | 3.1 | 0.06 | Oct 10, 2018 | An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… | ||
| CVE-2018-8481 | Low | 0.21 | 3.1 | 0.06 | Oct 10, 2018 | An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… | ||
| CVE-2025-59280 | Low | 0.20 | 3.1 | 0.00 | Oct 14, 2025 | Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. | ||
| CVE-2025-21312 | Low | 0.16 | 2.4 | 0.01 | Jan 14, 2025 | Windows Smart Card Reader Information Disclosure Vulnerability | ||
| CVE-2025-59294 | Low | 0.14 | 2.1 | 0.01 | Oct 14, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. |
- risk 0.27cvss 4.2epss 0.01
Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
- risk 0.27cvss 4.2epss 0.02
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete…
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
- risk 0.26cvss 4.0epss 0.01
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticated attacker could…
- risk 0.25cvss 3.9epss 0.00
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
- risk 0.23cvss 3.5epss 0.01
External control of file name or path in Windows Storage allows an authorized attacker to perform spoofing over a network.
- risk 0.23cvss 3.5epss 0.04
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is…
- risk 0.22cvss 3.3epss 0.11
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
- risk 0.22cvss 3.3epss 0.03
Media Foundation Information Disclosure Vulnerability
- risk 0.22cvss 3.3epss 0.07
Windows NTFS Denial of Service Vulnerability
- risk 0.22cvss 3.3epss 0.01
Windows Digital Media Receiver Elevation of Privilege Vulnerability
- risk 0.22cvss 3.3epss 0.01
A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microsoft Defender Security Feature Bypass Vulnerability'.
- risk 0.22cvss 3.3epss 0.02
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
- risk 0.21cvss 3.3epss 0.01
Windows NTFS Elevation of Privilege Vulnerability
- risk 0.21cvss 3.3epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.21cvss 3.1epss 0.06
An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…
- risk 0.21cvss 3.1epss 0.06
An information disclosure vulnerability exists when Windows Media Player improperly discloses file information, aka "Windows Media Player Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…
- risk 0.20cvss 3.1epss 0.00
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
- risk 0.16cvss 2.4epss 0.01
Windows Smart Card Reader Information Disclosure Vulnerability
- risk 0.14cvss 2.1epss 0.01
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
Page 232 of 248