cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 78 of 198
CVE-2024-38238P3HIGHCVSS 7.8fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38238 [HIGH] CWE-122 CVE-2024-38238: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-20682P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.53292024-01-09
CVE-2024-20682 [HIGH] CWE-822 CVE-2024-20682: Windows Cryptographic Services Remote Code Execution Vulnerability Windows Cryptographic Services Remote Code Execution Vulnerability
nvd
CVE-2024-38057P3HIGHCVSS 7.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38057 [HIGH] CWE-125 CVE-2024-38057: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-33056P3HIGHCVSS 7.5fixed in 10.0.17763.7434≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-33056 [HIGH] CWE-284 CVE-2025-33056: Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38134P3HIGHCVSS 7.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38134 [HIGH] CWE-125 CVE-2024-38134: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-26677P3HIGHCVSS 7.5fixed in 10.0.17763.7314≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-26677 [HIGH] CWE-400 CVE-2025-26677: Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker Uncontrolled resource consumption in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21375P3HIGHCVSS 7.8fixed in 10.0.17763.6893≥ 10.0.17763.0, < 10.0.17763.68932025-02-11
CVE-2025-21375 [HIGH] CWE-20 CVE-2025-21375: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-27476P3HIGHCVSS 7.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27476 [HIGH] CWE-416 CVE-2025-27476: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27467P3HIGHCVSS 7.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27467 [HIGH] CWE-416 CVE-2025-27467: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27730P3HIGHCVSS 7.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27730 [HIGH] CWE-415 CVE-2025-27730: Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49716P3HIGHCVSS 7.5fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49716 [HIGH] CWE-400 CVE-2025-49716: Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny servic Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-24044P3HIGHCVSS 7.8fixed in 10.0.17763.7009≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24044 [HIGH] CWE-416 CVE-2025-24044: Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26679P3HIGHCVSS 7.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-26679 [HIGH] CWE-416 CVE-2025-26679: Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges lo Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-33075P3HIGHCVSS 7.8fixed in 10.0.17763.7434≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-33075 [HIGH] CWE-59 CVE-2025-33075: Improper link resolution before file access ('link following') in Windows Installer allows an author Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-44812P3HIGHCVSS 7.8fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-44812 [HIGH] CWE-190 CVE-2026-44812: Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-44803P3HIGHCVSS 7.8fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-44803 [HIGH] CWE-190 CVE-2026-44803: Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute c Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-24072P3HIGHCVSS 7.8fixed in 10.0.17763.7009≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24072 [HIGH] CWE-416 CVE-2025-24072: Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker t Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49667P3HIGHCVSS 7.8fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49667 [HIGH] CWE-415 CVE-2025-49667: Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49721P3HIGHCVSS 7.8fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49721 [HIGH] CWE-122 CVE-2025-49721: Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate pri Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-53800P3HIGHCVSS 7.8fixed in 10.0.17763.7792≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-53800 [HIGH] CWE-1419 CVE-2025-53800: No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privi No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase