cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 163 of 198
CVE-2025-21310P4MEDIUMCVSS 6.6fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21310 [MEDIUM] CWE-125 CVE-2025-21310: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2018-8592P4MEDIUMCVSS 6.4v(Server Core installation)2018-11-14
CVE-2018-8592 [MEDIUM] CVE-2018-8592: An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physic An elevation of privilege vulnerability exists in Windows 10 version 1809 when installed from physical media (USB, DVD, etc, aka "Windows Elevation Of Privilege Vulnerability." This affects Windows 10, Windows Server 2019.
nvd
CVE-2025-21263P4MEDIUMCVSS 6.6fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21263 [MEDIUM] CWE-125 CVE-2025-21263: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21327P4MEDIUMCVSS 6.6fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21327 [MEDIUM] CWE-125 CVE-2025-21327: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21265P4MEDIUMCVSS 6.6fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21265 [MEDIUM] CWE-125 CVE-2025-21265: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21261P4MEDIUMCVSS 6.6fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21261 [MEDIUM] CWE-125 CVE-2025-21261: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21341P4MEDIUMCVSS 6.6fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21341 [MEDIUM] CWE-125 CVE-2025-21341: Windows Digital Media Elevation of Privilege Vulnerability Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2021-27079P4MEDIUMCVSS 5.7≥ 10.0.0, < publication2021-04-13
CVE-2021-27079 [MEDIUM] CVE-2021-27079: Windows Media Photo Codec Information Disclosure Vulnerability Windows Media Photo Codec Information Disclosure Vulnerability
nvd
CVE-2023-24944P4MEDIUMCVSS 6.5≥ 10.0.17763.0, < 10.0.17763.43772023-05-09
CVE-2023-24944 [MEDIUM] CWE-843 CVE-2023-24944: Windows Bluetooth Driver Information Disclosure Vulnerability Windows Bluetooth Driver Information Disclosure Vulnerability
nvd
CVE-2019-1187P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1187 [MEDIUM] CWE-611 CVE-2019-1187: A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XM A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited this vulnerability could cause a denial of service against an XML application. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to an XML application
nvd
CVE-2021-26866P4MEDIUMCVSS 6.1≥ 10.0.0, < publication2021-03-11
CVE-2021-26866 [MEDIUM] CWE-59 CVE-2021-26866: Windows Update Service Elevation of Privilege Vulnerability Windows Update Service Elevation of Privilege Vulnerability
nvd
CVE-2022-41086P4MEDIUMCVSS 6.4≥ 10.0.17763.0, < 10.0.17763.36502022-11-09
CVE-2022-41086 [MEDIUM] CWE-362 CVE-2022-41086: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-24503P4MEDIUMCVSS 5.3≥ 10.0.17763.0, < 10.0.17763.26862022-03-09
CVE-2022-24503 [MEDIUM] CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2023-21693P4MEDIUMCVSS 5.7≥ 10.0.17763.0, < 10.0.17763.40102023-02-14
CVE-2023-21693 [MEDIUM] CWE-125 CVE-2023-21693: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-20692P4MEDIUMCVSS 5.7fixed in 10.0.17763.5329≥ 10.0.17763.0, < 10.0.17763.53292024-01-09
CVE-2024-20692 [MEDIUM] CWE-326 CVE-2024-20692: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2019-1227P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2019-08-14
CVE-2019-1227 [MEDIUM] CWE-200 CVE-2019-1227: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted applic
nvd
CVE-2024-43547P4MEDIUMCVSS 5.9fixed in 10.0.17763.6414≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43547 [MEDIUM] CWE-325 CVE-2024-43547: Windows Kerberos Information Disclosure Vulnerability Windows Kerberos Information Disclosure Vulnerability
nvd
CVE-2019-1171P4MEDIUMCVSS 5.6≥ 10.0.0, < publication2019-08-14
CVE-2019-1171 [MEDIUM] CWE-200 CVE-2019-1171: An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An atta An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulne
nvd
CVE-2018-8492P4MEDIUMCVSS 5.3v(Server Core installation)2018-10-10
CVE-2018-8492 [MEDIUM] CVE-2018-8492: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2025-21269P4MEDIUMCVSS 4.3fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21269 [MEDIUM] CWE-41 CVE-2025-21269: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase