cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 83 of 198
CVE-2024-49114P3HIGHCVSS 7.8fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49114 [HIGH] CWE-820 CVE-2024-49114: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38133P3HIGHCVSS 7.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38133 [HIGH] CWE-138 CVE-2024-38133: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38070P3HIGHCVSS 7.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38070 [HIGH] CWE-693 CVE-2024-38070: Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
nvd
CVE-2024-38215P3HIGHCVSS 7.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38215 [HIGH] CWE-190 CVE-2024-38215: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-36701P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.49742023-10-10
CVE-2023-36701 [HIGH] CWE-125 CVE-2023-36701: Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-30079P3HIGHCVSS 7.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-30079 [HIGH] CWE-126 CVE-2024-30079: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2024-43501P3HIGHCVSS 7.8fixed in 10.0.17763.6414≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43501 [HIGH] CWE-59 CVE-2024-43501: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-27739P3HIGHCVSS 7.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-27739 [HIGH] CWE-822 CVE-2025-27739: Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21359P3HIGHCVSS 7.8fixed in 10.0.17763.6893≥ 10.0.17763.0, < 10.0.17763.68932025-02-11
CVE-2025-21359 [HIGH] CWE-284 CVE-2025-21359: Windows Kernel Security Feature Bypass Vulnerability Windows Kernel Security Feature Bypass Vulnerability
nvd
CVE-2026-48575P3HIGHCVSS 7.9fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-48575 [HIGH] CWE-693 CVE-2026-48575: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48570P3HIGHCVSS 7.9fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-48570 [HIGH] CWE-693 CVE-2026-48570: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48568P3HIGHCVSS 7.9fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-48568 [HIGH] CWE-693 CVE-2026-48568: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-45588P3HIGHCVSS 7.9fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45588 [HIGH] CWE-693 CVE-2026-45588: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-21271P3HIGHCVSS 7.8fixed in 10.0.17763.6775≥ 10.0.17763.0, < 10.0.17763.67752025-01-14
CVE-2025-21271 [HIGH] CWE-126 CVE-2025-21271: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-59200P3HIGHCVSS 7.7fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-59200 [HIGH] CWE-73 CVE-2025-59200: Concurrent execution using shared resource with improper synchronization ('race condition') in Data Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2026-48578P3HIGHCVSS 7.9fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-48578 [HIGH] CWE-284 CVE-2026-48578: Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges l Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38153P3HIGHCVSS 7.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38153 [HIGH] CWE-367 CVE-2024-38153: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38191P3HIGHCVSS 7.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-08-13
CVE-2024-38191 [HIGH] CWE-362 CVE-2024-38191: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-24059P3HIGHCVSS 7.8fixed in 10.0.17763.7009≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24059 [HIGH] CWE-125 CVE-2025-24059: Incorrect conversion between numeric types in Windows Common Log File System Driver allows an author Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-32017P3HIGHCVSS 7.8fixed in 10.0.17763.4499≥ 10.0.17763.0, < 10.0.17763.44992023-06-14
CVE-2023-32017 [HIGH] CWE-125 CVE-2023-32017: Microsoft PostScript Printer Driver Remote Code Execution Vulnerability Microsoft PostScript Printer Driver Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase