Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 137 of 198
CVE-2025-49734P3HIGHCVSS 7.0fixed in 10.0.17763.7792≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-49734 [HIGH] CWE-923 CVE-2025-49734: Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50297P3HIGHCVSS 7.0fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50297 [HIGH] CWE-284 CVE-2026-50297: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50325P3HIGHCVSS 7.0fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50325 [HIGH] CWE-284 CVE-2026-50325: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall
Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34341P3HIGHCVSS 7.0fixed in 10.0.17763.8755≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-34341 [HIGH] CWE-415 CVE-2026-34341: Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32086P3HIGHCVSS 7.0fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32086 [HIGH] CWE-362 CVE-2026-32086: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32150P3HIGHCVSS 7.0fixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-32150 [HIGH] CWE-362 CVE-2026-32150: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50356P3HIGHCVSS 7.0fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50356 [HIGH] CWE-362 CVE-2026-50356: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49784P3HIGHCVSS 7.0fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-49784 [HIGH] CWE-362 CVE-2026-49784: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-28223P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28223 [MEDIUM] CWE-416 CVE-2023-28223: Windows Domain Name Service Remote Code Execution Vulnerability
Windows Domain Name Service Remote Code Execution Vulnerability
nvd
CVE-2025-32715P3MEDIUMCVSS 6.5fixed in 10.0.17763.7434≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-32715 [MEDIUM] CWE-125 CVE-2025-32715: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2022-30214P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.31652022-07-12
CVE-2022-30214 [MEDIUM] CWE-362 CVE-2022-30214: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-32043P3MEDIUMCVSS 6.8≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-32043 [MEDIUM] CWE-327 CVE-2023-32043: Windows Remote Desktop Security Feature Bypass Vulnerability
Windows Remote Desktop Security Feature Bypass Vulnerability
nvd
CVE-2026-50492P3MEDIUMCVSS 6.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50492 [MEDIUM] CWE-122 CVE-2026-50492: Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker t
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2025-55225P3MEDIUMCVSS 6.5fixed in 10.0.17763.7792≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-55225 [MEDIUM] CWE-125 CVE-2025-55225: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-28308P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28308 [MEDIUM] CWE-416 CVE-2023-28308: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28278P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28278 [MEDIUM] CWE-591 CVE-2023-28278: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28305P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28305 [MEDIUM] CWE-416 CVE-2023-28305: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28306P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28306 [MEDIUM] CWE-416 CVE-2023-28306: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28307P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28307 [MEDIUM] CWE-416 CVE-2023-28307: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28255P3MEDIUMCVSS 6.6≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28255 [MEDIUM] CWE-591 CVE-2023-28255: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd