Windows Server 2019
by Microsoft
CVEs (4,947)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-24094 | Cri | 0.65 | 9.8 | 0.22 | Feb 25, 2021 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2021-24078 | Cri | 0.65 | 9.8 | 0.11 | Feb 25, 2021 | Windows DNS Server Remote Code Execution Vulnerability | ||
| CVE-2020-1467 | Cri | 0.65 | 10.0 | 0.04 | Aug 17, 2020 | An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log… | ||
| CVE-2020-1112 | Cri | 0.65 | 9.9 | 0.04 | May 21, 2020 | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'. | ||
| CVE-2019-1384 | Cri | 0.65 | 9.9 | 0.06 | Nov 12, 2019 | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass… | ||
| CVE-2019-1365 | Cri | 0.65 | 9.9 | 0.04 | Oct 10, 2019 | An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the… | ||
| CVE-2019-1182 | Cri | 0.65 | 9.8 | 0.17 | Aug 14, 2019 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and… | ||
| CVE-2018-8626 | Cri | 0.65 | 9.8 | 0.21 | Dec 12, 2018 | A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10,… | ||
| CVE-2026-65791 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2026 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62893 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2026 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-62878 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2026 | Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-47291 | Cri | 0.64 | 9.8 | 0.23 | Jun 9, 2026 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-44815 | Cri | 0.64 | 9.8 | 0.01 | Jun 9, 2026 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-60724 | Cri | 0.64 | 9.8 | 0.06 | Nov 11, 2025 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-49708 | Cri | 0.64 | 9.9 | 0.01 | Oct 14, 2025 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-53766 | Cri | 0.64 | 9.8 | 0.07 | Aug 12, 2025 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-21307 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2025 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | ||
| CVE-2024-43639 | Cri | 0.64 | 9.8 | 0.09 | Nov 12, 2024 | Windows KDC Proxy Remote Code Execution Vulnerability | ||
| CVE-2024-38199 | Cri | 0.64 | 9.8 | 0.02 | Aug 13, 2024 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability | ||
| CVE-2024-38178 | Hig | 0.64 | 7.5 | 0.41 | KEV | Aug 13, 2024 | Scripting Engine Memory Corruption Vulnerability |
- risk 0.65cvss 9.8epss 0.22
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.11
Windows DNS Server Remote Code Execution Vulnerability
- risk 0.65cvss 10.0epss 0.04
An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log…
- risk 0.65cvss 9.9epss 0.04
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
- risk 0.65cvss 9.9epss 0.06
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass…
- risk 0.65cvss 9.9epss 0.04
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the…
- risk 0.65cvss 9.8epss 0.17
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and…
- risk 0.65cvss 9.8epss 0.21
A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10,…
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.02
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.23
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.06
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.9epss 0.01
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.07
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.02
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.09
Windows KDC Proxy Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
- risk 0.64cvss 7.5epss 0.41
Scripting Engine Memory Corruption Vulnerability
Page 7 of 248