cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 121 of 198
CVE-2026-32093P3HIGHCVSS 7.0fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32093 [HIGH] CWE-122 CVE-2026-32093: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-36394P3HIGHCVSS 7.0≥ 10.0.17763.0, < 10.0.17763.51222023-11-14
CVE-2023-36394 [HIGH] CWE-59 CVE-2023-36394: Windows Search Service Elevation of Privilege Vulnerability Windows Search Service Elevation of Privilege Vulnerability
nvd
CVE-2024-26233P3MEDIUMCVSS 6.6fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26233 [MEDIUM] CWE-416 CVE-2024-26233: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2024-26224P3MEDIUMCVSS 6.6fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26224 [MEDIUM] CWE-416 CVE-2024-26224: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2024-26223P3MEDIUMCVSS 6.6fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26223 [MEDIUM] CWE-416 CVE-2024-26223: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2024-26231P3MEDIUMCVSS 6.6fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26231 [MEDIUM] CWE-416 CVE-2024-26231: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2024-26227P3MEDIUMCVSS 6.6fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26227 [MEDIUM] CWE-416 CVE-2024-26227: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2026-24285P3HIGHCVSS 7.0fixed in 10.0.17763.8511≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-24285 [HIGH] CWE-416 CVE-2026-24285: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29968P3MEDIUMCVSS 6.5fixed in 10.0.17763.7314≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29968 [MEDIUM] CWE-20 CVE-2025-29968: Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized atta Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.
nvd
CVE-2026-32073P3HIGHCVSS 7.0fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32073 [HIGH] CWE-416 CVE-2026-32073: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60716P3HIGHCVSS 7.0fixed in 10.0.17763.8027≥ 10.0.17763.0, < 10.0.17763.80272025-11-11
CVE-2025-60716 [HIGH] CWE-416 CVE-2025-60716: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32075P3HIGHCVSS 7.0fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32075 [HIGH] CWE-416 CVE-2026-32075: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347P3HIGHCVSS 7.0fixed in 10.0.17763.8755≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42984P3HIGHCVSS 7.0fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42984 [HIGH] CWE-416 CVE-2026-42984: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56173P3HIGHCVSS 7.0fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-56173 [HIGH] CWE-416 CVE-2026-56173: Use after free in Windows WebView allows an authorized attacker to elevate privileges locally. Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58629P3HIGHCVSS 7.0fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-58629 [HIGH] CWE-416 CVE-2026-58629: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50397P3HIGHCVSS 7.0fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50397 [HIGH] CWE-416 CVE-2026-50397: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50166P3MEDIUMCVSS 6.5fixed in 10.0.17763.7678≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-50166 [MEDIUM] CWE-190 CVE-2025-50166: Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized a Integer overflow or wraparound in Windows Distributed Transaction Coordinator allows an authorized attacker to disclose information over a network.
nvd
CVE-2020-1577P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1577 [MEDIUM] CVE-2020-1577: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted
nvd
CVE-2025-59185P3MEDIUMCVSS 6.5fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-59185 [MEDIUM] CWE-73 CVE-2025-59185: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd
Microsoft Windows Server 2019 vulnerabilities | cvebase