Msrc Windows Server 2019 vulnerabilities
4,184 known vulnerabilities affecting msrc/windows_server_2019.
Total CVEs
4,184
CISA KEV
151
actively exploited
Public exploits
123
Exploited in wild
142
Severity breakdown
CRITICAL90HIGH2890MEDIUM1182LOW22
Vulnerabilities
Page 142 of 210
CVE-2021-27094MEDIUMCVSS 4.42021-04-13
CVE-2021-27094 [MEDIUM] Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
Windows ELAM: Windows ELAM
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5001339
msrc
CVE-2021-28316MEDIUMCVSS 4.22021-04-13
CVE-2021-28316 [MEDIUM] Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
Windows WLAN Auto Config Service: Windows WLAN Auto Config Service
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site
msrc
CVE-2021-28444MEDIUMCVSS 5.72021-04-13
CVE-2021-28444 [MEDIUM] Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
FAQ: What configurations or versions could be at risk from this vulnerability?
This bypass could affect any Hyper-V configurations that are using Router Guard.
What is the exposure if the vulnerability was bypassed?
Certain packets that would normally be blocked or dropped could be processed. This could allow an attacker to bypass set policy, potentially influencin
msrc
CVE-2021-26413MEDIUMCVSS 6.22021-04-13
CVE-2021-26413 [MEDIUM] Windows Installer Spoofing Vulnerability
Windows Installer Spoofing Vulnerability
Windows Installer: Windows Installer
Microsoft: Microsoft
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5001339
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB50013
msrc
CVE-2021-26417MEDIUMCVSS 5.52021-04-13
CVE-2021-26417 [MEDIUM] Windows Overlay Filter Information Disclosure Vulnerability
Windows Overlay Filter Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
Windows Overlay Filter: Windows Overlay Filt
msrc
CVE-2021-28309MEDIUMCVSS 5.52021-04-13
CVE-2021-28309 [MEDIUM] Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the contents of Kernel memory. An attacker could read the contents of Kernel memory from a user mode process.
Windows Kernel: Windows Kernel
Microsoft: Microsoft
Impact: Information Disclo
msrc
CVE-2021-28325MEDIUMCVSS 6.52021-04-13
CVE-2021-28325 [MEDIUM] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory and kernel memory - unintentional read access to memory contents in kernel space from a user mode process.
Windows SMB Server: Windows SMB Server
Microsoft: Microsoft
Impact
msrc
CVE-2021-28328MEDIUMCVSS 6.52021-04-13
CVE-2021-28328 [MEDIUM] Windows DNS Information Disclosure Vulnerability
Windows DNS Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
Microsoft Windows DNS: Microsoft Windows DNS
Microsoft: Microsoft
msrc
CVE-2021-28326MEDIUMCVSS 5.52021-04-13
CVE-2021-28326 [MEDIUM] Windows AppX Deployment Server Denial of Service Vulnerability
Windows AppX Deployment Server Denial of Service Vulnerability
Windows AppX Deployment Extensions: Windows AppX Deployment Extensions
Microsoft: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=K
msrc
CVE-2021-28323MEDIUMCVSS 6.52021-04-13
CVE-2021-28323 [MEDIUM] Windows DNS Information Disclosure Vulnerability
Windows DNS Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
FAQ: Does this vulnerability affect both DNS Servers and DNS Clien
msrc
CVE-2021-28311MEDIUMCVSS 6.52021-04-13
CVE-2021-28311 [MEDIUM] Windows Application Compatibility Cache Denial of Service Vulnerability
Windows Application Compatibility Cache Denial of Service Vulnerability
Windows Application Compatibility Cache: Windows Application Compatibility Cache
Microsoft: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft
msrc
CVE-2021-27092MEDIUMCVSS 6.82021-04-13
CVE-2021-27092 [MEDIUM] Azure AD Web Sign-in Security Feature Bypass Vulnerability
Azure AD Web Sign-in Security Feature Bypass Vulnerability
Azure AD Web Sign-in: Azure AD Web Sign-in
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5001330
Reference: https://s
msrc
CVE-2021-28447MEDIUMCVSS 4.42021-04-13
CVE-2021-28447 [MEDIUM] Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
Windows Early Launch Antimalware Driver: Windows Early Launch Antimalware Driver
Microsoft: Microsoft
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalo
msrc
CVE-2021-28312LOWCVSS 3.32021-04-13
CVE-2021-28312 [LOW] Windows NTFS Denial of Service Vulnerability
Windows NTFS Denial of Service Vulnerability
Windows NTFS: Windows NTFS
Microsoft: Microsoft
Impact: Denial of Service
Exploit Status: Publicly Disclosed:Yes;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5001342
Reference: https://support.microsoft.com/help/5001342
Reference: https:
msrc
CVE-2021-26897CRITICALCVSS 9.82021-03-09
CVE-2021-26897 [CRITICAL] Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
FAQ: Can this vulnerability by mitigated by enabling Secure Zone Updates?
Enabling Secure Zone Updates constrains the potential sources of the attack, but does not completely prevent it. For example, a malicious insider could attack a “secure zone update” DNS server from a domain-joined computer. This is only a partial mitigation.
Does this vulnerability impact
msrc
CVE-2021-26894CRITICALCVSS 9.82021-03-09
CVE-2021-26894 [CRITICAL] Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
FAQ: Can this vulnerability by mitigated by enabling Secure Zone Updates?
Enabling Secure Zone Updates constrains the potential sources of the attack, but does not completely prevent it. For example, a malicious insider could attack a “secure zone update” DNS server from a domain-joined computer. This is only a partial mitigation.
Does this vulnerability impact
msrc
CVE-2021-26895CRITICALCVSS 9.82021-03-09
CVE-2021-26895 [CRITICAL] Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
FAQ: Can this vulnerability by mitigated by enabling Secure Zone Updates?
Enabling Secure Zone Updates constrains the potential sources of the attack, but does not completely prevent it. For example, a malicious insider could attack a “secure zone update” DNS server from a domain-joined computer. This is only a partial mitigation.
Does this vulnerability impact
msrc
CVE-2021-26877CRITICALCVSS 9.82021-03-09
CVE-2021-26877 [CRITICAL] Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
FAQ: Can this vulnerability by mitigated by enabling Secure Zone Updates?
Enabling Secure Zone Updates constrains the potential sources of the attack, but does not completely prevent it. For example, a malicious insider could attack a “secure zone update” DNS server from a domain-joined computer. This is only a partial mitigation.
Does this vulnerability impact
msrc
CVE-2021-26893CRITICALCVSS 9.82021-03-09
CVE-2021-26893 [CRITICAL] Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
FAQ: Can this vulnerability by mitigated by enabling Secure Zone Updates?
Enabling Secure Zone Updates constrains the potential sources of the attack, but does not completely prevent it. For example, a malicious insider could attack a “secure zone update” DNS server from a domain-joined computer. This is only a partial mitigation.
Does this vulnerability impact
msrc
CVE-2021-26881HIGHCVSS 7.52021-03-09
CVE-2021-26881 [HIGH] Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Windows Media: Windows Media
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5000809
Reference: htt
msrc