Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 141 of 198
CVE-2025-29958P3MEDIUMCVSS 6.5fixed in 10.0.17763.7314≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29958 [MEDIUM] CWE-908 CVE-2025-29958: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthor
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-29961P3MEDIUMCVSS 6.5fixed in 10.0.17763.7314≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29961 [MEDIUM] CWE-125 CVE-2025-29961: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-29352P4MEDIUMCVSS 6.5fixed in 10.0.17763.4499≥ 10.0.17763.0, < 10.0.17763.44992023-06-14
CVE-2023-29352 [MEDIUM] CVE-2023-29352: Windows Remote Desktop Security Feature Bypass Vulnerability
Windows Remote Desktop Security Feature Bypass Vulnerability
nvd
CVE-2025-29836P3MEDIUMCVSS 6.5fixed in 10.0.17763.7314≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29836 [MEDIUM] CWE-125 CVE-2025-29836: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2024-43487P3MEDIUMCVSS 6.5fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-43487 [MEDIUM] CWE-693 CVE-2024-43487: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2023-35308P3MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35308 [MEDIUM] CWE-73 CVE-2023-35308: Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2025-49681P3MEDIUMCVSS 6.5fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49681 [MEDIUM] CWE-125 CVE-2025-49681: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-27925P4MEDIUMCVSS 6.5fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-27925 [MEDIUM] CWE-416 CVE-2026-27925: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.
nvd
CVE-2021-38665P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.17763.23002021-11-10
CVE-2021-38665 [MEDIUM] CVE-2021-38665: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2019-1025P3MEDIUMCVSS 6.5≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-1025 [MEDIUM] CVE-2019-1025: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specif
nvd
CVE-2023-21677P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21677 [HIGH] CWE-822 CVE-2023-21677: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21683P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21683 [HIGH] CWE-476 CVE-2023-21683: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21527P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21527 [HIGH] CWE-191 CVE-2023-21527: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-35330P4HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35330 [HIGH] CWE-126 CVE-2023-35330: Windows Extended Negotiation Denial of Service Vulnerability
Windows Extended Negotiation Denial of Service Vulnerability
nvd
CVE-2023-21811P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.40102023-02-14
CVE-2023-21811 [HIGH] CWE-126 CVE-2023-21811: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-21700P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.40102023-02-14
CVE-2023-21700 [HIGH] CWE-476 CVE-2023-21700: Windows iSCSI Discovery Service Denial of Service Vulnerability
Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-21702P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.40102023-02-14
CVE-2023-21702 [HIGH] CWE-125 CVE-2023-21702: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-20588P4MEDIUMCVSS 5.5fixed in 10.0.17763.52062023-08-08
CVE-2023-20588 [MEDIUM] CWE-369 CVE-2023-20588: A division-by-zero error on some AMD processors can potentially return speculative data resulting i
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
nvd
CVE-2022-24490P3MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.28032022-04-15
CVE-2022-24490 [MEDIUM] CVE-2022-24490: Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
nvd
CVE-2022-38042P3HIGHCVSS 7.1≥ 10.0.17763.0, < 10.0.17763.35322022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd