Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 20 of 198
CVE-2026-49798P3CRITICALCVSS 9.3fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-49798 [CRITICAL] CWE-416 CVE-2026-49798: Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-26645P3HIGHCVSS 8.8fixed in 10.0.17763.6893≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-26645 [HIGH] CWE-23 CVE-2025-26645: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49164P3CRITICALCVSS 9.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-49164 [CRITICAL] CWE-122 CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to ex
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-35841P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.34062022-09-13
CVE-2022-35841 [HIGH] CVE-2022-35841: Windows Enterprise App Management Service Remote Code Execution Vulnerability
Windows Enterprise App Management Service Remote Code Execution Vulnerability
nvd
CVE-2025-53722P3HIGHCVSS 7.5fixed in 10.0.17763.7678≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-53722 [HIGH] CWE-400 CVE-2025-53722: Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker
Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-20678P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-20678 [HIGH] CWE-843 CVE-2024-20678: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-29137P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-29137 [HIGH] CVE-2022-29137: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22014P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-22014 [HIGH] CVE-2022-22014: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22013P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-22013 [HIGH] CVE-2022-22013: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-36423P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.51222023-11-14
CVE-2023-36423 [HIGH] CWE-122 CVE-2023-36423: Microsoft Remote Registry Service Remote Code Execution Vulnerability
Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2026-20840P3HIGHCVSS 7.8fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20840 [HIGH] CWE-122 CVE-2026-20840: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2025-59295P3HIGHCVSS 8.8fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-59295 [HIGH] CWE-122 CVE-2025-59295: Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-24051P3HIGHCVSS 8.8fixed in 10.0.17763.7009≥ 10.0.17763.0, < 10.0.17763.70092025-03-11
CVE-2025-24051 [HIGH] CWE-122 CVE-2025-24051: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-35641P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.52062023-12-12
CVE-2023-35641 [HIGH] CWE-682 CVE-2023-35641: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2025-49724P3HIGHCVSS 8.8fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49724 [HIGH] CWE-416 CVE-2025-49724: Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to exec
Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49757P3HIGHCVSS 8.8fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-08-12
CVE-2025-49757 [HIGH] CWE-122 CVE-2025-49757: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-50163P3HIGHCVSS 8.8fixed in 10.0.17763.7678≥ 10.0.17763.0, < 10.0.17763.76782025-08-12
CVE-2025-50163 [HIGH] CWE-122 CVE-2025-50163: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-54113P3HIGHCVSS 8.8fixed in 10.0.17763.7792≥ 10.0.17763.0, < 10.0.17763.77922025-09-09
CVE-2025-54113 [HIGH] CWE-122 CVE-2025-54113: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-25188P3HIGHCVSS 8.8fixed in 10.0.17763.8511≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-25188 [HIGH] CWE-122 CVE-2026-25188: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate p
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2026-50505P3HIGHCVSS 8.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50505 [HIGH] CWE-416 CVE-2026-50505: Use after free in Windows Message Queuing allows an authorized attacker to execute code over a netwo
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd