cbcvebase.

Microsoft Windows Server 2019 vulnerabilities

3,952 known vulnerabilities affecting microsoft/windows_server_2019.

Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16

Vulnerabilities

Page 19 of 198
CVE-2024-43593P2HIGHCVSS 8.8fixed in 10.0.17763.6414≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43593 [HIGH] CWE-20 CVE-2024-43593: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43592P2HIGHCVSS 8.8fixed in 10.0.17763.6414≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43592 [HIGH] CWE-20 CVE-2024-43592: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38260P2HIGHCVSS 8.8fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38260 [HIGH] CWE-908 CVE-2024-38260: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2025-64678P2HIGHCVSS 8.8fixed in 10.0.17763.8027≥ 10.0.17763.0, < 10.0.17763.80272025-12-09
CVE-2025-64678 [HIGH] CWE-122 CVE-2025-64678: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50369P2HIGHCVSS 8.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50369 [HIGH] CWE-362 CVE-2026-50369: Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privilege Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-21993P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.25652022-02-09
CVE-2022-21993 [HIGH] CVE-2022-21993: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
nvd
CVE-2023-21708P2CRITICALCVSS 9.8≥ 10.0.17763.0, < 10.0.17763.41312023-03-14
CVE-2023-21708 [CRITICAL] CWE-191 CVE-2023-21708: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-34494P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.17763.20612021-07-14
CVE-2021-34494 [HIGH] CVE-2021-34494: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2024-43452P3HIGHCVSS 7.5fixed in 10.0.17763.6532≥ 10.0.17763.0, < 10.0.17763.65322024-11-12
CVE-2024-43452 [HIGH] CWE-367 CVE-2024-43452: Windows Registry Elevation of Privilege Vulnerability Windows Registry Elevation of Privilege Vulnerability
nvd
CVE-2022-29129P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-29129 [HIGH] CVE-2022-29129: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29128P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-29128 [HIGH] CVE-2022-29128: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29131P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-29131 [HIGH] CVE-2022-29131: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29141P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-29141 [HIGH] CVE-2022-29141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2025-26647P2HIGHCVSS 8.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-26647 [HIGH] CWE-20 CVE-2025-26647: Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges ov Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-42985P3HIGHCVSS 8.8fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42985 [HIGH] CWE-416 CVE-2026-42985: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49178P3HIGHCVSS 8.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-49178 [HIGH] CWE-122 CVE-2026-49178: Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to exec Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
nvd
CVE-2021-36958P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.17763.21832021-08-12
CVE-2021-36958 [HIGH] CVE-2021-36958: <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly pe A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
nvd
CVE-2024-30078P3HIGHCVSS 8.8fixed in 10.0.17763.5936≥ 10.0.17763.0, < 10.0.17763.59362024-06-11
CVE-2024-30078 [HIGH] CWE-20 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability Windows Wi-Fi Driver Remote Code Execution Vulnerability
nvd
CVE-2025-33070P3HIGHCVSS 8.1fixed in 10.0.17763.7434≥ 10.0.17763.0, < 10.0.17763.74342025-06-10
CVE-2025-33070 [HIGH] CWE-908 CVE-2025-33070: Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privile Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2024-38240P3CRITICALCVSS 9.8fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38240 [CRITICAL] CWE-125 CVE-2024-38240: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd