cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 82 of 198
CVE-2022-30164P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.30462022-06-15
CVE-2022-30164 [HIGH] CVE-2022-30164: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
nvd
CVE-2023-36047P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.51222023-11-14
CVE-2023-36047 [HIGH] CWE-59 CVE-2023-36047: Windows Authentication Elevation of Privilege Vulnerability Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2024-49090P3HIGHCVSS 7.8fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49090 [HIGH] CWE-822 CVE-2024-49090: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-49088P3HIGHCVSS 7.8fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49088 [HIGH] CWE-126 CVE-2024-49088: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-0790P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0790 [HIGH] CVE-2020-0790: <p>A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if th
nvd
CVE-2024-26173P3HIGHCVSS 7.8fixed in 10.0.17763.5576≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-26173 [HIGH] CWE-20 CVE-2024-26173: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26178P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-26178 [HIGH] CWE-122 CVE-2024-26178: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-1080P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-1080 [HIGH] CVE-2020-1080: <p>An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to pro An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system. This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used
nvd
CVE-2020-1047P3HIGHCVSS 7.8≥ 10.0.0, < publication2020-10-16
CVE-2020-1047 [HIGH] CVE-2020-1047: <p>An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to pro An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system. This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used
nvd
CVE-2025-21180P3HIGHCVSS 7.8fixed in 10.0.17763.7009≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-21180 [HIGH] CWE-122 CVE-2025-21180: Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.
nvd
CVE-2019-1028P3HIGHCVSS 7.8≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-1028 [HIGH] CVE-2019-1028: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
CVE-2019-1022P3HIGHCVSS 7.8≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-1022 [HIGH] CVE-2019-1022: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
CVE-2019-1026P3HIGHCVSS 7.8≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-1026 [HIGH] CVE-2019-1026: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
CVE-2019-1027P3HIGHCVSS 7.8≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-1027 [HIGH] CVE-2019-1027: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
CVE-2019-1021P3HIGHCVSS 7.8≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-1021 [HIGH] CVE-2019-1021: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
CVE-2024-30018P3HIGHCVSS 7.8fixed in 10.0.17763.5820≥ 10.0.17763.0, < 10.0.17763.58202024-05-14
CVE-2024-30018 [HIGH] CWE-59 CVE-2024-30018: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-32724P3HIGHCVSS 7.5fixed in 10.0.17763.7434≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-32724 [HIGH] CWE-400 CVE-2025-32724: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-20693P3HIGHCVSS 7.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-20693 [HIGH] CWE-426 CVE-2024-20693: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26176P3HIGHCVSS 7.8fixed in 10.0.17763.5576≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-26176 [HIGH] CWE-126 CVE-2024-26176: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-1007P3HIGHCVSS 7.8≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-1007 [HIGH] CWE-269 CVE-2019-1007: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be r
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase