Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
170
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 17 of 198
CVE-2025-26670P2HIGHCVSS 8.1fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-26670 [HIGH] CWE-416 CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-25177P2HIGHCVSS 8.8fixed in 10.0.17763.8511≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-25177 [HIGH] CWE-641 CVE-2026-25177: Improper restriction of names for files and other resources in Active Directory Domain Services allo
Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-54121P2HIGHCVSS 8.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-54121 [HIGH] CWE-285 CVE-2026-54121: Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacke
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-48564P2HIGHCVSS 8.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-48564 [HIGH] CWE-122 CVE-2026-48564: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50444P2HIGHCVSS 8.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50444 [HIGH] CWE-306 CVE-2026-50444: Missing authentication for critical function in Windows Server Update Service allows an authorized a
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50502P2HIGHCVSS 8.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50502 [HIGH] CWE-1220 CVE-2026-50502: Insufficient granularity of access control in Windows Event Logging Service allows an authorized att
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
nvd
CVE-2022-37954P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.34062022-09-13
CVE-2022-37954 [HIGH] CVE-2022-37954: DirectX Graphics Kernel Elevation of Privilege Vulnerability
DirectX Graphics Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-34722P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.34062022-09-13
CVE-2022-34722 [CRITICAL] CVE-2022-34722: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2022-35744P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.32872023-05-31
CVE-2022-35744 [CRITICAL] CVE-2022-35744: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2023-36606P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.49742023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2020-16898P2HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16898 [HIGH] CVE-2020-16898: <p>A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICM
A remote code execution vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could gain the ability to execute code on the target server or client.
To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Adverti
nvd
CVE-2019-0959P3HIGHCVSS 7.0PoC≥ 10.0.17763.0, < publication2019-06-12
CVE-2019-0959 [HIGH] CVE-2019-0959: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2026-56159P2CRITICALCVSS 9.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-56159 [CRITICAL] CWE-122 CVE-2026-56159: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50447P2CRITICALCVSS 9.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50447 [CRITICAL] CWE-122 CVE-2026-50447: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58594P2CRITICALCVSS 9.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-58594 [CRITICAL] CWE-190 CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-42990P2CRITICALCVSS 9.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-42990 [CRITICAL] CWE-122 CVE-2026-42990: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-57089P2CRITICALCVSS 9.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-57089 [CRITICAL] CWE-416 CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized at
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-49116P3HIGHCVSS 8.1fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.70092024-12-12
CVE-2024-49116 [HIGH] CWE-416 CVE-2024-49116: Windows Remote Desktop Services Remote Code Execution Vulnerability
Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
CVE-2024-30017P2HIGHCVSS 8.8fixed in 10.0.17763.5820≥ 10.0.17763.0, < 10.0.17763.58202024-05-14
CVE-2024-30017 [HIGH] CWE-122 CVE-2024-30017: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2024-38104P2HIGHCVSS 8.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38104 [HIGH] CWE-822 CVE-2024-38104: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd