Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33786 | Hig | 0.53 | 8.1 | 0.02 | Jul 14, 2021 | Windows LSA Security Feature Bypass Vulnerability | ||
| CVE-2021-33781 | Hig | 0.53 | 8.1 | 0.02 | Jul 14, 2021 | Azure AD Security Feature Bypass Vulnerability | ||
| CVE-2021-33779 | Hig | 0.53 | 8.1 | 0.02 | Jul 14, 2021 | Windows AD FS Security Feature Bypass Vulnerability | ||
| CVE-2021-28445 | Hig | 0.53 | 8.1 | 0.03 | Apr 13, 2021 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2021-24086 | Hig | 0.53 | 7.5 | 0.59 | Feb 25, 2021 | Windows TCP/IP Denial of Service Vulnerability | ||
| CVE-2021-1722 | Hig | 0.53 | 8.1 | 0.02 | Feb 25, 2021 | Windows Fax Service Remote Code Execution Vulnerability | ||
| CVE-2020-1400 | Hig | 0.53 | 7.8 | 0.24 | Jul 14, 2020 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407. | ||
| CVE-2020-0665 | Hig | 0.53 | 8.1 | 0.04 | Feb 11, 2020 | An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'. | ||
| CVE-2019-1424 | Hig | 0.53 | 8.1 | 0.03 | Nov 12, 2019 | A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'. | ||
| CVE-2019-1311 | Hig | 0.53 | 7.8 | 0.36 | Oct 10, 2019 | A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'. | ||
| CVE-2019-0734 | Hig | 0.53 | 8.1 | 0.04 | May 16, 2019 | An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this… | ||
| CVE-2018-8423 | Hig | 0.53 | 7.8 | 0.33 | Oct 10, 2018 | A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server… | ||
| CVE-2026-33826 | Hig | 0.52 | 8.0 | 0.01 | Apr 14, 2026 | Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. | ||
| CVE-2026-27912 | Hig | 0.52 | 8.0 | 0.00 | Apr 14, 2026 | Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2026-26111 | Hig | 0.52 | 8.0 | 0.01 | Mar 10, 2026 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-25173 | Hig | 0.52 | 8.0 | 0.01 | Mar 10, 2026 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-25172 | Hig | 0.52 | 8.0 | 0.01 | Mar 10, 2026 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-20931 | Hig | 0.52 | 8.0 | 0.01 | Jan 13, 2026 | External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network. | ||
| CVE-2025-62452 | Hig | 0.52 | 8.0 | 0.01 | Nov 11, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | ||
| CVE-2025-60715 | Hig | 0.52 | 8.0 | 0.01 | Nov 11, 2025 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. |
- risk 0.53cvss 8.1epss 0.02
Windows LSA Security Feature Bypass Vulnerability
- risk 0.53cvss 8.1epss 0.02
Azure AD Security Feature Bypass Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows AD FS Security Feature Bypass Vulnerability
- risk 0.53cvss 8.1epss 0.03
Windows Network File System Remote Code Execution Vulnerability
- risk 0.53cvss 7.5epss 0.59
Windows TCP/IP Denial of Service Vulnerability
- risk 0.53cvss 8.1epss 0.02
Windows Fax Service Remote Code Execution Vulnerability
- risk 0.53cvss 7.8epss 0.24
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407.
- risk 0.53cvss 8.1epss 0.04
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
- risk 0.53cvss 8.1epss 0.03
A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
- risk 0.53cvss 7.8epss 0.36
A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.
- risk 0.53cvss 8.1epss 0.04
An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this…
- risk 0.53cvss 7.8epss 0.33
A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server…
- risk 0.52cvss 8.0epss 0.01
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
- risk 0.52cvss 8.0epss 0.00
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
- risk 0.52cvss 8.0epss 0.01
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.01
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.01
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.01
External control of file name or path in Windows Telephony Service allows an authorized attacker to elevate privileges over an adjacent network.
- risk 0.52cvss 8.0epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.01
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
Page 48 of 248