cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 161 of 198
CVE-2025-62208P4MEDIUMCVSS 5.5fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-11-11
CVE-2025-62208 [MEDIUM] CWE-532 CVE-2025-62208: Insertion of sensitive information into log file in Windows License Manager allows an authorized att Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2026-57083P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-57083 [MEDIUM] CWE-908 CVE-2026-57083: Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-43585P4MEDIUMCVSS 5.5fixed in 10.0.17763.6414≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43585 [MEDIUM] CWE-693 CVE-2024-43585: Code Integrity Guard Security Feature Bypass Vulnerability Code Integrity Guard Security Feature Bypass Vulnerability
nvd
CVE-2025-55325P4MEDIUMCVSS 5.5fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-55325 [MEDIUM] CWE-126 CVE-2025-55325: Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose in Buffer over-read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50681P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50681 [MEDIUM] CWE-200 CVE-2026-50681: Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50352P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50352 [MEDIUM] CWE-200 CVE-2026-50352: Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50389P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50389 [MEDIUM] CWE-200 CVE-2026-50389: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an author Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59513P4MEDIUMCVSS 5.5fixed in 10.0.17763.8027≥ 10.0.17763.0, < 10.0.17763.80272025-11-11
CVE-2025-59513 [MEDIUM] CWE-125 CVE-2025-59513: Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to discl Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45594P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45594 [MEDIUM] CWE-200 CVE-2026-45594: Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) S Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42969P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42969 [MEDIUM] CWE-908 CVE-2026-42969: Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclos Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
nvd
CVE-2025-59260P4MEDIUMCVSS 5.5fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-59260 [MEDIUM] CWE-200 CVE-2025-59260: Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Dri Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-45634P4MEDIUMCVSS 5.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45634 [MEDIUM] CWE-125 CVE-2026-45634: Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information loca Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
nvd
CVE-2026-34328P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-34328 [MEDIUM] CWE-200 CVE-2026-34328: Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an author Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-32212P4MEDIUMCVSS 5.5fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32212 [MEDIUM] CWE-59 CVE-2026-32212: Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-40422P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-40422 [MEDIUM] CWE-908 CVE-2026-40422: Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose inf Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50401P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50401 [MEDIUM] CWE-125 CVE-2026-50401: Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclo Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50455P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50455 [MEDIUM] CWE-908 CVE-2026-50455: Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-58638P4MEDIUMCVSS 5.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-58638 [MEDIUM] CWE-325 CVE-2026-58638: Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-32214P4MEDIUMCVSS 5.5fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32214 [MEDIUM] CWE-284 CVE-2026-32214: Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to discl Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2021-41337P4MEDIUMCVSS 4.9≥ 10.0.0, < 10.0.17763.22372021-10-13
CVE-2021-41337 [MEDIUM] CVE-2021-41337: Active Directory Security Feature Bypass Vulnerability Active Directory Security Feature Bypass Vulnerability
nvd