Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 155 of 198
CVE-2025-50158P4HIGHCVSS 7.0fixed in 10.0.17763.7678≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-50158 [HIGH] CWE-367 CVE-2025-50158: Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to
Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2021-33764P4MEDIUMCVSS 5.9≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-33764 [MEDIUM] CVE-2021-33764: Windows Key Distribution Center Information Disclosure Vulnerability
Windows Key Distribution Center Information Disclosure Vulnerability
nvd
CVE-2023-21560P4MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.38872023-01-10
CVE-2023-21560 [MEDIUM] CWE-122 CVE-2023-21560: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28269P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28269 [MEDIUM] CWE-122 CVE-2023-28269: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28249P4MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28249 [MEDIUM] CWE-863 CVE-2023-28249: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2024-38013P4MEDIUMCVSS 6.7fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38013 [MEDIUM] CWE-59 CVE-2024-38013: Microsoft Windows Server Backup Elevation of Privilege Vulnerability
Microsoft Windows Server Backup Elevation of Privilege Vulnerability
nvd
CVE-2024-49101P4MEDIUMCVSS 6.6fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49101 [MEDIUM] CWE-125 CVE-2024-49101: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2024-49109P4MEDIUMCVSS 6.6fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49109 [MEDIUM] CWE-125 CVE-2024-49109: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2026-45608P4MEDIUMCVSS 6.8fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45608 [MEDIUM] CWE-125 CVE-2026-45608: Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information lo
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-49081P4MEDIUMCVSS 6.6fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49081 [MEDIUM] CWE-122 CVE-2024-49081: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2024-49094P4MEDIUMCVSS 6.6fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49094 [MEDIUM] CWE-122 CVE-2024-49094: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2021-34493P4MEDIUMCVSS 6.7≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-34493 [MEDIUM] CWE-269 CVE-2021-34493: Windows Partition Management Driver Elevation of Privilege Vulnerability
Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-49111P4MEDIUMCVSS 6.6fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49111 [MEDIUM] CWE-125 CVE-2024-49111: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability
nvd
CVE-2022-35754P4MEDIUMCVSS 6.7≥ 10.0.17763.0, < 10.0.17763.32872023-05-31
CVE-2022-35754 [MEDIUM] CVE-2022-35754: Unified Write Filter Elevation of Privilege Vulnerability
Unified Write Filter Elevation of Privilege Vulnerability
nvd
CVE-2022-22028P4MEDIUMCVSS 5.9≥ 10.0.17763.0, < 10.0.17763.31652022-07-12
CVE-2022-22028 [MEDIUM] CVE-2022-22028: Windows Network File System Information Disclosure Vulnerability
Windows Network File System Information Disclosure Vulnerability
nvd
CVE-2021-41338P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.17763.22372021-10-13
CVE-2021-41338 [MEDIUM] CVE-2021-41338: Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
nvd
CVE-2024-21316P4MEDIUMCVSS 6.1fixed in 10.0.17763.5329≥ 10.0.17763.0, < 10.0.17763.53292024-01-09
CVE-2024-21316 [MEDIUM] CWE-20 CVE-2024-21316: Windows Server Key Distribution Service Security Feature Bypass
Windows Server Key Distribution Service Security Feature Bypass
nvd
CVE-2022-34709P4MEDIUMCVSS 6.0≥ 10.0.17763.0, < 10.0.17763.32872022-08-09
CVE-2022-34709 [MEDIUM] CWE-843 CVE-2022-34709: Windows Defender Credential Guard Security Feature Bypass Vulnerability
Windows Defender Credential Guard Security Feature Bypass Vulnerability
nvd
CVE-2026-20818P4MEDIUMCVSS 6.2fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20818 [MEDIUM] CWE-532 CVE-2026-20818: Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker t
Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-59258P4MEDIUMCVSS 6.2fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-59258 [MEDIUM] CWE-532 CVE-2025-59258: Insertion of sensitive information into log file in Active Directory Federation Services allows an u
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
nvd