Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 36 of 198
CVE-2024-21368P3HIGHCVSS 8.8fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21368 [HIGH] CWE-122 CVE-2024-21368: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21359P3HIGHCVSS 8.8fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21359 [HIGH] CWE-122 CVE-2024-21359: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21391P3HIGHCVSS 8.8fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21391 [HIGH] CWE-197 CVE-2024-21391: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21352P3HIGHCVSS 8.8fixed in 10.0.17763.5458≥ 10.0.17763.0, < 10.0.17763.54582024-02-13
CVE-2024-21352 [HIGH] CWE-197 CVE-2024-21352: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2025-59199P3HIGHCVSS 7.8fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-59199 [HIGH] CWE-284 CVE-2025-59199: Improper access control in Software Protection Platform (SPP) allows an authorized attacker to eleva
Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-20872P3MEDIUMCVSS 6.5fixed in 10.0.17763.8276≥ 10.0.17763.0, < 10.0.17763.82762026-01-13
CVE-2026-20872 [MEDIUM] CWE-73 CVE-2026-20872: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-43517P3HIGHCVSS 8.8fixed in 10.0.17763.6414≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43517 [HIGH] CWE-122 CVE-2024-43517: Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
nvd
CVE-2024-38131P3HIGHCVSS 8.8fixed in 10.0.17763.6189≥ 10.0.17763.0, < 10.0.17763.61892024-08-13
CVE-2024-38131 [HIGH] CWE-591 CVE-2024-38131: Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
nvd
CVE-2024-38053P3HIGHCVSS 8.8fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38053 [HIGH] CWE-416 CVE-2024-38053: Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43518P3HIGHCVSS 8.8fixed in 10.0.17763.6414≥ 10.0.17763.0, < 10.0.17763.64142024-10-08
CVE-2024-43518 [HIGH] CWE-122 CVE-2024-43518: Windows Telephony Server Remote Code Execution Vulnerability
Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-29964P3HIGHCVSS 8.8fixed in 10.0.17763.7314≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29964 [HIGH] CWE-122 CVE-2025-29964: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29963P3HIGHCVSS 8.8fixed in 10.0.17763.7314≥ 10.0.17763.0, < 10.0.17763.73142025-05-13
CVE-2025-29963 [HIGH] CWE-122 CVE-2025-29963: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49688P3HIGHCVSS 8.8fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49688 [HIGH] CWE-415 CVE-2025-49688: Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to e
Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-33679P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.34062022-09-13
CVE-2022-33679 [HIGH] CVE-2022-33679: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2026-49170P3HIGHCVSS 7.8fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-49170 [HIGH] CWE-285 CVE-2026-49170: Insufficient granularity of access control in Windows StateRepository API allows an authorized attac
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38049P3HIGHCVSS 8.1fixed in 10.0.17763.6054≥ 10.0.17763.0, < 10.0.17763.60542024-07-09
CVE-2024-38049 [HIGH] CWE-73 CVE-2024-38049: Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
nvd
CVE-2026-42989P3HIGHCVSS 7.8fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42989 [HIGH] CWE-59 CVE-2026-42989: Improper link resolution before file access ('link following') in Winlogon allows an authorized atta
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
nvd
CVE-2021-1694P3CRITICALCVSS 9.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1694 [CRITICAL] CWE-269 CVE-2021-1694: Windows Update Stack Elevation of Privilege Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2024-38045P3HIGHCVSS 8.1fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38045 [HIGH] CWE-122 CVE-2024-38045: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2024-49124P3HIGHCVSS 8.1fixed in 10.0.17763.6659≥ 10.0.17763.0, < 10.0.17763.66592024-12-12
CVE-2024-49124 [HIGH] CWE-362 CVE-2024-49124: Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
nvd