Windows Server 2019
by Microsoft
CVEs (4,941)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24491 | Cri | 0.66 | 9.8 | 0.33 | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2021-24074 | Cri | 0.66 | 9.8 | 0.26 | Feb 25, 2021 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2020-1464 | Hig | 0.66 | 7.8 | 0.41 | KEV | Aug 17, 2020 | A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features… | |
| CVE-2020-0683 | Hig | 0.66 | 7.8 | 0.08 | KEV | Feb 11, 2020 | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686. | |
| CVE-2019-0863 | Hig | 0.66 | 7.8 | 0.05 | KEV | May 16, 2019 | An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. | |
| CVE-2019-0725 | Cri | 0.66 | 9.8 | 0.26 | May 16, 2019 | A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | ||
| CVE-2019-0697 | Cri | 0.66 | 9.8 | 0.30 | Apr 9, 2019 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726. | ||
| CVE-2025-47981 | Cri | 0.65 | 9.8 | 0.32 | Jul 8, 2025 | Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-30397 | Hig | 0.65 | 7.5 | 0.27 | KEV | May 13, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | |
| CVE-2023-36397 | Cri | 0.65 | 9.8 | 0.18 | Nov 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-44487 | Hig | 0.65 | 7.5 | 1.00 | KEV | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| CVE-2023-36802 | Hig | 0.65 | 7.8 | 0.26 | KEV | Sep 12, 2023 | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | |
| CVE-2023-21692 | Cri | 0.65 | 9.8 | 0.21 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2022-37969 | Hig | 0.65 | 7.8 | 0.28 | KEV | Sep 13, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2022-26925 | Hig | 0.65 | 8.1 | 0.11 | KEV | May 10, 2022 | Windows LSA Spoofing Vulnerability | |
| CVE-2021-26432 | Cri | 0.65 | 9.8 | 0.11 | Aug 12, 2021 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | ||
| CVE-2021-34458 | Cri | 0.65 | 9.9 | 0.03 | Jul 16, 2021 | Windows Kernel Remote Code Execution Vulnerability | ||
| CVE-2021-33742 | Hig | 0.65 | 7.5 | 0.59 | KEV | Jun 8, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability | |
| CVE-2021-26897 | Cri | 0.65 | 9.8 | 0.14 | Mar 11, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2021-26877 | Cri | 0.65 | 9.8 | 0.19 | Mar 11, 2021 | Windows DNS Server Remote Code Execution Vulnerability |
- risk 0.66cvss 9.8epss 0.33
Windows Network File System Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.26
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.66cvss 7.8epss 0.41
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features…
- risk 0.66cvss 7.8epss 0.08
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
- risk 0.66cvss 7.8epss 0.05
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
- risk 0.66cvss 9.8epss 0.26
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
- risk 0.66cvss 9.8epss 0.30
A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.
- risk 0.65cvss 9.8epss 0.32
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 7.5epss 0.27
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 9.8epss 0.18
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.65cvss 7.5epss 1.00
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- risk 0.65cvss 7.8epss 0.26
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
- risk 0.65cvss 9.8epss 0.21
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.65cvss 7.8epss 0.28
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.65cvss 8.1epss 0.11
Windows LSA Spoofing Vulnerability
- risk 0.65cvss 9.8epss 0.11
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
- risk 0.65cvss 9.9epss 0.03
Windows Kernel Remote Code Execution Vulnerability
- risk 0.65cvss 7.5epss 0.59
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.14
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.19
Windows DNS Server Remote Code Execution Vulnerability
Page 6 of 248