Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 138 of 198
CVE-2023-28256P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28256 [MEDIUM] CWE-591 CVE-2023-28256: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2025-54097P3MEDIUMCVSS 6.5fixed in 10.0.17763.7792≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-54097 [MEDIUM] CWE-125 CVE-2025-54097: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54096P3MEDIUMCVSS 6.5fixed in 10.0.17763.7792≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-54096 [MEDIUM] CWE-125 CVE-2025-54096: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54095P3MEDIUMCVSS 6.5fixed in 10.0.17763.7792≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-54095 [MEDIUM] CWE-125 CVE-2025-54095: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-54126P3MEDIUMCVSS 6.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-54126 [MEDIUM] CWE-125 CVE-2026-54126: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2021-31968P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.17763.19992021-06-08
CVE-2021-31968 [HIGH] CVE-2021-31968: Windows Remote Desktop Services Denial of Service Vulnerability
Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2021-33785P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-33785 [HIGH] CVE-2021-33785: Windows AF_UNIX Socket Provider Denial of Service Vulnerability
Windows AF_UNIX Socket Provider Denial of Service Vulnerability
nvd
CVE-2022-21889P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.24522022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.24522022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-36707P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.49742023-10-10
CVE-2023-36707 [HIGH] CWE-20 CVE-2023-36707: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2022-35833P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.34062022-09-13
CVE-2022-35833 [HIGH] CVE-2022-35833: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-36585P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.49742023-10-10
CVE-2023-36585 [HIGH] CWE-20 CVE-2023-36585: Windows upnphost.dll Denial of Service Vulnerability
Windows upnphost.dll Denial of Service Vulnerability
nvd
CVE-2023-36395P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.51222023-11-14
CVE-2023-36395 [HIGH] CWE-190 CVE-2023-36395: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2023-36720P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.49742023-10-10
CVE-2023-36720 [HIGH] CVE-2023-36720: Windows Mixed Reality Developer Tools Denial of Service Vulnerability
Windows Mixed Reality Developer Tools Denial of Service Vulnerability
nvd
CVE-2022-34701P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.32872022-08-09
CVE-2022-34701 [HIGH] CWE-400 CVE-2022-34701: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2020-1256P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1256 [MEDIUM] CVE-2020-1256: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2020-1097P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1097 [MEDIUM] CVE-2020-1097: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2022-33645P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.35322022-10-11
CVE-2022-33645 [HIGH] CVE-2022-33645: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2023-24931P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-24931 [HIGH] CWE-125 CVE-2023-24931: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-21757P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21757 [HIGH] CWE-476 CVE-2023-21757: Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
nvd