Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 31 of 198
CVE-2023-24868P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.41312023-03-14
CVE-2023-24868 [HIGH] CWE-122 CVE-2023-24868: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2023-23406P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.41312023-03-14
CVE-2023-23406 [HIGH] CWE-122 CVE-2023-23406: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2023-24913P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.41312023-03-14
CVE-2023-24913 [HIGH] CWE-122 CVE-2023-24913: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2023-21684P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.40102023-02-14
CVE-2023-21684 [HIGH] CWE-191 CVE-2023-21684: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2025-21286P3HIGHCVSS 8.8fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21286 [HIGH] CWE-122 CVE-2025-21286: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21266P3HIGHCVSS 8.8fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21266 [HIGH] CWE-122 CVE-2025-21266: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21273P3HIGHCVSS 8.8fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21273 [HIGH] CWE-122 CVE-2025-21273: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21282P3HIGHCVSS 8.8fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21282 [HIGH] CWE-122 CVE-2025-21282: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-27481P3HIGHCVSS 8.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27481 [HIGH] CWE-121 CVE-2025-27481: Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45602P3CRITICALCVSS 9.1fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45602 [CRITICAL] CWE-349 CVE-2026-45602: No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering ov
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
nvd
CVE-2022-30163P3HIGHCVSS 8.5≥ 10.0.17763.0, < 10.0.17763.30462022-06-15
CVE-2022-30163 [HIGH] CWE-362 CVE-2022-30163: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2026-32225P3HIGHCVSS 8.8fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32225 [HIGH] CWE-693 CVE-2026-32225: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-53131P3HIGHCVSS 8.8fixed in 10.0.17763.7678≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-53131 [HIGH] CWE-122 CVE-2025-53131: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-54982P3HIGHCVSS 8.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-54982 [HIGH] CWE-191 CVE-2026-54982: Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an una
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-26663P3HIGHCVSS 8.1fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-26663 [HIGH] CWE-416 CVE-2025-26663: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-17090P3CRITICALCVSS 9.8≥ 10.0.0, < publication2020-11-11
CVE-2020-17090 [CRITICAL] CVE-2020-17090: Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
nvd
CVE-2025-21294P3HIGHCVSS 8.1fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2026-40415P3HIGHCVSS 8.1fixed in 10.0.17763.8755≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-40415 [HIGH] CWE-416 CVE-2026-40415: Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-17040P3CRITICALCVSS 9.8≥ 10.0.0, < publication2020-11-11
CVE-2020-17040 [CRITICAL] CVE-2020-17040: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2026-45635P3HIGHCVSS 8.1fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45635 [HIGH] CWE-843 CVE-2026-45635: Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll)
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd