Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 134 of 198
CVE-2023-35348P3MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35348 [MEDIUM] CWE-522 CVE-2023-35348: Active Directory Federation Service Security Feature Bypass Vulnerability
Active Directory Federation Service Security Feature Bypass Vulnerability
nvd
CVE-2025-58729P3MEDIUMCVSS 6.5fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-58729 [MEDIUM] CWE-1287 CVE-2025-58729: Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an auth
Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2023-35351P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35351 [MEDIUM] CWE-416 CVE-2023-35351: Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
nvd
CVE-2023-35346P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35346 [MEDIUM] CWE-591 CVE-2023-35346: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35345P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35345 [MEDIUM] CWE-591 CVE-2023-35345: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35344P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35344 [MEDIUM] CWE-591 CVE-2023-35344: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35310P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35310 [MEDIUM] CWE-591 CVE-2023-35310: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2026-42903P3MEDIUMCVSS 6.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42903 [MEDIUM] CWE-476 CVE-2026-42903: Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
nvd
CVE-2022-21883P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.24522022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2026-26155P3MEDIUMCVSS 6.5fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-26155 [MEDIUM] CWE-126 CVE-2026-26155: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2026-49799P3MEDIUMCVSS 6.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-49799 [MEDIUM] CWE-400 CVE-2026-49799: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo
Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
nvd
CVE-2022-21848P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.24522022-01-11
CVE-2022-21848 [HIGH] CVE-2022-21848: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2021-43219P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.17763.23662021-12-15
CVE-2021-43219 [HIGH] CVE-2021-43219: DirectX Graphics Kernel File Denial of Service Vulnerability
DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2021-31183P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-31183 [HIGH] CVE-2021-31183: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2021-26879P3HIGHCVSS 7.5≥ 10.0.0, < publication2021-03-11
CVE-2021-26879 [HIGH] CVE-2021-26879: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2022-34724P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.34062022-09-13
CVE-2022-34724 [HIGH] CVE-2022-34724: Windows DNS Server Denial of Service Vulnerability
Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2019-0972P3MEDIUMCVSS 6.5≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-0972 [MEDIUM] CVE-2019-0972: This security update corrects a denial of service in the Local Security Authority Subsystem Service
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause a denial of service on the target system's LSASS service, which triggers an automatic rebo
nvd
CVE-2022-34720P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.34062022-09-13
CVE-2022-34720 [HIGH] CVE-2022-34720: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-26915P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.28032022-04-15
CVE-2022-26915 [HIGH] CVE-2022-26915: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2022-30202P3HIGHCVSS 7.0≥ 10.0.17763.0, < 10.0.17763.31652022-07-12
CVE-2022-30202 [HIGH] CVE-2022-30202: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd