cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 104 of 198
CVE-2022-41052P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.36502022-11-09
CVE-2022-41052 [HIGH] CVE-2022-41052: Windows Graphics Component Remote Code Execution Vulnerability Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2020-1538P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1538 [HIGH] CVE-2020-1538: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how the Wind
nvd
CVE-2020-1517P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1517 [HIGH] CVE-2020-1517: An elevation of privilege vulnerability exists when the Windows File Server Resource Management Serv An elevation of privilege vulnerability exists when the Windows File Server Resource Management Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by
nvd
CVE-2020-1526P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1526 [HIGH] CVE-2020-1526: An elevation of privilege vulnerability exists when the Windows Network Connection Broker improperly An elevation of privilege vulnerability exists when the Windows Network Connection Broker improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting ho
nvd
CVE-2022-30131P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.30462022-06-15
CVE-2022-30131 [HIGH] CVE-2022-30131: Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-1488P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1488 [HIGH] CWE-269 CVE-2020-1488: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update addresses the vulnerability by corr
nvd
CVE-2020-0912P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0912 [HIGH] CVE-2020-0912: <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correct
nvd
CVE-2023-21817P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.40102023-02-14
CVE-2023-21817 [HIGH] CWE-287 CVE-2023-21817: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-35771P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.32872022-08-09
CVE-2022-35771 [HIGH] CWE-269 CVE-2022-35771: Windows Defender Credential Guard Elevation of Privilege Vulnerability Windows Defender Credential Guard Elevation of Privilege Vulnerability
nvd
CVE-2020-1146P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1146 [HIGH] CVE-2020-1146: <p>An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handle An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how the Micr
nvd
CVE-2021-1652P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1652 [HIGH] CWE-269 CVE-2021-1652: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1653P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1653 [HIGH] CWE-269 CVE-2021-1653: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1646P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1646 [HIGH] CWE-269 CVE-2021-1646: Windows WLAN Service Elevation of Privilege Vulnerability Windows WLAN Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1693P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1693 [HIGH] CWE-269 CVE-2021-1693: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1654P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1654 [HIGH] CWE-269 CVE-2021-1654: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1655P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1655 [HIGH] CWE-269 CVE-2021-1655: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2025-27741P3HIGHCVSS 7.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27741 [HIGH] CWE-125 CVE-2025-27741: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-21822P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.40102023-02-14
CVE-2023-21822 [HIGH] CWE-416 CVE-2023-21822: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-36726P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.49742023-10-10
CVE-2023-36726 [HIGH] CWE-416 CVE-2023-36726: Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
nvd
CVE-2021-26891P3HIGHCVSS 7.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26891 [HIGH] CVE-2021-26891: Windows Container Execution Agent Elevation of Privilege Vulnerability Windows Container Execution Agent Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase