Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-8489 | Hig | 0.55 | 8.4 | 0.04 | Oct 10, 2018 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2,… | ||
| CVE-2025-59254 | Hig | 0.54 | 7.8 | 0.01 | Oct 14, 2025 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49730 | Hig | 0.54 | 7.8 | 0.01 | Jul 8, 2025 | Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49683 | Hig | 0.54 | 7.8 | 0.02 | Jul 8, 2025 | Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-47987 | Hig | 0.54 | 7.8 | 0.02 | Jul 8, 2025 | Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-33071 | Hig | 0.54 | 8.1 | 0.17 | Jun 10, 2025 | Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21309 | Hig | 0.54 | 8.1 | 0.15 | Jan 14, 2025 | Windows Remote Desktop Services Remote Code Execution Vulnerability | ||
| CVE-2024-49122 | Hig | 0.54 | 8.1 | 0.20 | Dec 12, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2024-30038 | Hig | 0.54 | 7.8 | 0.03 | May 14, 2024 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2024-26212 | Hig | 0.54 | 7.5 | 0.63 | Apr 9, 2024 | DHCP Server Service Denial of Service Vulnerability | ||
| CVE-2024-21407 | Hig | 0.54 | 8.1 | 0.16 | Mar 12, 2024 | Windows Hyper-V Remote Code Execution Vulnerability | ||
| CVE-2023-36606 | Hig | 0.54 | 7.5 | 0.67 | Oct 10, 2023 | Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | ||
| CVE-2023-38039 | Hig | 0.54 | 7.5 | 0.62 | Sep 15, 2023 | When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an… | ||
| CVE-2023-28293 | Hig | 0.54 | 7.8 | 0.03 | Apr 11, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-28220 | Hig | 0.54 | 8.1 | 0.15 | Apr 11, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2023-28219 | Hig | 0.54 | 8.1 | 0.15 | Apr 11, 2023 | Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-44666 | Hig | 0.54 | 7.8 | 0.41 | Dec 13, 2022 | Windows Contacts Remote Code Execution Vulnerability | ||
| CVE-2022-37954 | Hig | 0.54 | 7.8 | 0.45 | Sep 13, 2022 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | ||
| CVE-2021-31955 | Med | 0.54 | 5.5 | 0.81 | KEV | Jun 8, 2021 | Windows Kernel Information Disclosure Vulnerability | |
| CVE-2020-17140 | Hig | 0.54 | 8.1 | 0.12 | Dec 10, 2020 | Windows SMB Information Disclosure Vulnerability |
- risk 0.55cvss 8.4epss 0.04
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2,…
- risk 0.54cvss 7.8epss 0.01
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 7.8epss 0.01
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 7.8epss 0.02
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
- risk 0.54cvss 7.8epss 0.02
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
- risk 0.54cvss 8.1epss 0.17
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
- risk 0.54cvss 8.1epss 0.15
Windows Remote Desktop Services Remote Code Execution Vulnerability
- risk 0.54cvss 8.1epss 0.20
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.03
Win32k Elevation of Privilege Vulnerability
- risk 0.54cvss 7.5epss 0.63
DHCP Server Service Denial of Service Vulnerability
- risk 0.54cvss 8.1epss 0.16
Windows Hyper-V Remote Code Execution Vulnerability
- risk 0.54cvss 7.5epss 0.67
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- risk 0.54cvss 7.5epss 0.62
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an…
- risk 0.54cvss 7.8epss 0.03
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.54cvss 8.1epss 0.15
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.54cvss 8.1epss 0.15
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.41
Windows Contacts Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.45
DirectX Graphics Kernel Elevation of Privilege Vulnerability
- risk 0.54cvss 5.5epss 0.81
Windows Kernel Information Disclosure Vulnerability
- risk 0.54cvss 8.1epss 0.12
Windows SMB Information Disclosure Vulnerability
Page 40 of 248