Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 32 of 198
CVE-2026-45599P3HIGHCVSS 8.1fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-45599 [HIGH] CWE-416 CVE-2026-45599: Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21204P3HIGHCVSS 7.8fixed in 10.0.17763.7136≥ 10.0.17763.0, < 10.0.17763.71362025-04-08
CVE-2025-21204 [HIGH] CWE-59 CVE-2025-21204: Improper link resolution before file access ('link following') in Windows Update Stack allows an aut
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-43455P3CRITICALCVSS 9.8fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-43455 [CRITICAL] CWE-20 CVE-2024-43455: Windows Remote Desktop Licensing Service Spoofing Vulnerability
Windows Remote Desktop Licensing Service Spoofing Vulnerability
nvd
CVE-2020-1285P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1285 [HIGH] CVE-2020-1285: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users who
nvd
CVE-2020-1509P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1509 [HIGH] CVE-2020-1509: An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LS
An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service.
The security update addresses the vul
nvd
CVE-2026-33829P4MEDIUMCVSS 4.3PoCfixed in 10.0.17763.8644≥ 10.0.17763.0, < 10.0.17763.86442026-04-14
CVE-2026-33829 [MEDIUM] CWE-200 CVE-2026-33829: Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauth
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-24541P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.28032022-04-15
CVE-2022-24541 [HIGH] CVE-2022-24541: Windows Server Service Remote Code Execution Vulnerability
Windows Server Service Remote Code Execution Vulnerability
nvd
CVE-2022-30153P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.30462022-06-15
CVE-2022-30153 [HIGH] CVE-2022-30153: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30161P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.30462022-06-15
CVE-2022-30161 [HIGH] CVE-2022-30161: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29139P3HIGHCVSS 8.8≥ 10.0.17763.0, < 10.0.17763.29282022-05-10
CVE-2022-29139 [HIGH] CVE-2022-29139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2024-26166P3HIGHCVSS 8.8fixed in 10.0.17763.5576≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-26166 [HIGH] CWE-122 CVE-2024-26166: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21450P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-21450 [HIGH] CWE-190 CVE-2024-21450: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21440P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-21440 [HIGH] CWE-197 CVE-2024-21440: Microsoft ODBC Driver Remote Code Execution Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-26162P3HIGHCVSS 8.8fixed in 10.0.17763.5576≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-26162 [HIGH] CWE-681 CVE-2024-26162: Microsoft ODBC Driver Remote Code Execution Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2026-24289P3HIGHCVSS 7.8fixed in 10.0.17763.8511≥ 10.0.17763.0, < 10.0.17763.85112026-03-10
CVE-2026-24289 [HIGH] CWE-416 CVE-2026-24289: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26210P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26210 [HIGH] CWE-122 CVE-2024-26210: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-26244P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.56962024-04-09
CVE-2024-26244 [HIGH] CWE-191 CVE-2024-26244: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-26159P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-26159 [HIGH] CWE-122 CVE-2024-26159: Microsoft ODBC Driver Remote Code Execution Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21451P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-21451 [HIGH] CWE-197 CVE-2024-21451: Microsoft ODBC Driver Remote Code Execution Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-21444P3HIGHCVSS 8.8fixed in 10.0.17763.5696≥ 10.0.17763.0, < 10.0.17763.55762024-03-12
CVE-2024-21444 [HIGH] CWE-190 CVE-2024-21444: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd