Microsoft Windows Server 2019 vulnerabilities
3,952 known vulnerabilities affecting microsoft/windows_server_2019.
Total CVEs
3,952
CISA KEV
125
actively exploited
Public exploits
113
Exploited in wild
171
Severity breakdown
CRITICAL126HIGH2786MEDIUM1024LOW16
Vulnerabilities
Page 57 of 198
CVE-2026-50695P3HIGHCVSS 7.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50695 [HIGH] CWE-121 CVE-2026-50695: Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-35309P3HIGHCVSS 7.5≥ 10.0.17763.0, < 10.0.17763.46452023-07-11
CVE-2023-35309 [HIGH] CWE-591 CVE-2023-35309: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2025-55326P3HIGHCVSS 7.5fixed in 10.0.17763.7919≥ 10.0.17763.0, < 10.0.17763.79192025-10-14
CVE-2025-55326 [HIGH] CWE-416 CVE-2025-55326: Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to exe
Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50368P3HIGHCVSS 7.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50368 [HIGH] CWE-121 CVE-2026-50368: Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50411P3HIGHCVSS 7.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50411 [HIGH] CWE-121 CVE-2026-50411: Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized a
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-54983P3HIGHCVSS 7.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-54983 [HIGH] CWE-121 CVE-2026-54983: Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized a
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-35386P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.47372023-08-08
CVE-2023-35386 [HIGH] CWE-125 CVE-2023-35386: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2026-50504P3HIGHCVSS 7.5fixed in 10.0.17763.9020≥ 10.0.17763.0, < 10.0.17763.90202026-07-14
CVE-2026-50504 [HIGH] CWE-126 CVE-2026-50504: Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information ov
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-35382P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.47372023-08-08
CVE-2023-35382 [HIGH] CWE-416 CVE-2023-35382: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-55231P3HIGHCVSS 7.5fixed in 10.0.17763.7783≥ 10.0.17763.0, < 10.0.17763.75582025-08-21
CVE-2025-55231 [HIGH] CWE-362 CVE-2025-55231: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-42992P3HIGHCVSS 7.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-42992 [HIGH] CWE-122 CVE-2026-42992: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-44799P3HIGHCVSS 7.5fixed in 10.0.17763.8880≥ 10.0.17763.0, < 10.0.17763.88802026-06-09
CVE-2026-44799 [HIGH] CWE-122 CVE-2026-44799: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49666P3HIGHCVSS 7.2fixed in 10.0.17763.7558≥ 10.0.17763.0, < 10.0.17763.75582025-07-08
CVE-2025-49666 [HIGH] CWE-122 CVE-2025-49666: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a ne
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
nvd
CVE-2026-32161P3HIGHCVSS 7.5fixed in 10.0.17763.8755≥ 10.0.17763.0, < 10.0.17763.87552026-05-12
CVE-2026-32161 [HIGH] CWE-362 CVE-2026-32161: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2020-1525P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1525 [HIGH] CWE-787 CVE-2020-1525: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2022-35756P3HIGHCVSS 7.8≥ 10.0.17763.0, < 10.0.17763.32872023-05-31
CVE-2022-35756 [HIGH] CVE-2022-35756: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-30025P3HIGHCVSS 7.8fixed in 10.0.17763.5820≥ 10.0.17763.0, < 10.0.17763.58202024-05-14
CVE-2024-30025 [HIGH] CWE-125 CVE-2024-30025: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-28244P3HIGHCVSS 8.1≥ 10.0.17763.0, < 10.0.17763.42522023-04-11
CVE-2023-28244 [HIGH] CWE-327 CVE-2023-28244: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-37966P3HIGHCVSS 8.1vN/A2022-11-09
CVE-2022-37966 [HIGH] CVE-2022-37966: Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
nvd
CVE-2024-38237P3HIGHCVSS 7.8fixed in 10.0.17763.6293≥ 10.0.17763.0, < 10.0.17763.62932024-09-10
CVE-2024-38237 [HIGH] CWE-122 CVE-2024-38237: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd