Windows Server Microsoft Windows Server

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Windows Server.

Recent Microsoft Windows Server Security Advisories

Advisory Title Published
CVE-2026-20856 CVE-2026-20856 Windows Server Update Service (WSUS) Remote Code Execution Vulnerability January 13, 2026
CVE-2025-59287 CVE-2025-59287 Windows Server Update Service (WSUS) Remote Code Execution Vulnerability October 14, 2025
CVE-2025-49666 CVE-2025-49666 Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability July 8, 2025
CVE-2025-25008 CVE-2025-25008 Windows Server Elevation of Privilege Vulnerability March 11, 2025
CVE-2024-38013 CVE-2024-38013 Microsoft Windows Server Backup Elevation of Privilege Vulnerability July 9, 2024
CVE-2024-21316 Windows Server Key Distribution Service Security Feature Bypass January 9, 2024
CVE-2023-35317 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability July 11, 2023
CVE-2023-32056 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability July 11, 2023
CVE-2023-32056 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability July 11, 2023
CVE-2023-32022 Windows Server Service Security Feature Bypass Vulnerability June 13, 2023

By the Year

In 2026 there have been 0 vulnerabilities in Microsoft Windows Server. Last year, in 2025 Windows Server had 3 security vulnerabilities published. Right now, Windows Server is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 3 6.73
2024 9 7.62
2023 9 7.44
2022 192 7.32
2021 54 7.30
2020 163 8.23
2019 181 7.88
2018 36 8.30

It may take a day or so for new Windows Server vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Windows Server Security Vulnerabilities

Jul 2025: Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
CVE-2025-49681 6.5 - Medium - July 08, 2025

Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Windows Server: Backup Operator Auth Esc for Arbitrary Code
CVE-2025-24286 4.9 - Medium - June 19, 2025

A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.

Win RCE for Domain Users via Remote Exploit
CVE-2025-23120 8.8 - High - March 20, 2025

A vulnerability allowing remote code execution (RCE) for domain users.

Microsoft Windows LDAP RCE Vulnerability (CVE-2024-49127)
CVE-2024-49127 8.1 - High - December 12, 2024

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Race Condition

Microsoft Windows LDAP DoS via Directory Service
CVE-2024-49113 7.5 - High - December 12, 2024

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

Out-of-bounds Read

Windows RRAS Remote Code Execution via RRAS Service Vulnerability
CVE-2024-49104 8.8 - High - December 12, 2024

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Microsoft Windows SMB Denial of Service Vulnerability
CVE-2024-43642 7.5 - High - November 12, 2024

Windows SMB Denial of Service Vulnerability

Dangling pointer

RRAS Remote Code Execution Vulnerability in Windows Routing Service
CVE-2024-26200 8.8 - High - April 09, 2024

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Microsoft Windows DNS Server RCE Vulnerability
CVE-2024-26223 6.6 - Medium - April 09, 2024

Windows DNS Server Remote Code Execution Vulnerability

Windows File Server ResourceMgr Elevation of Privilege
CVE-2024-26216 7.3 - High - April 09, 2024

Windows File Server Resource Management Service Elevation of Privilege Vulnerability

Microsoft Windows LDAP DoS Vulnerability
CVE-2024-21356 6.5 - Medium - February 13, 2024

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

Inaccurate Distributed Trust Relationship Vulnerability (CVE20234566)
CVE-2023-4566 7.5 - High - January 16, 2024

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

Microsoft Windows Server RPC Runtime DoS Vulnerability
CVE-2023-33164 6.5 - Medium - July 11, 2023

Remote Procedure Call Runtime Denial of Service Vulnerability

MS Windows Server RPC Runtime DoS Vulnerability (CVE-2023-33173)
CVE-2023-33173 7.5 - High - July 11, 2023

Remote Procedure Call Runtime Denial of Service Vulnerability

Windows NFS RCE in Network File System (NFS) Service
CVE-2023-24941 9.8 - Critical - May 09, 2023

Windows Network File System Remote Code Execution Vulnerability

Windows DNS Server RCE via Query Parsing Vulnerability
CVE-2023-28307 6.6 - Medium - April 11, 2023

Windows DNS Server Remote Code Execution Vulnerability

Race Condition

Windows DNS RCE via Remote Code Execution
CVE-2023-28278 6.6 - Medium - April 11, 2023

Windows DNS Server Remote Code Execution Vulnerability

Race Condition

Windows SChannel DoS Vulnerability (CVE-2023-28233)
CVE-2023-28233 7.5 - High - April 11, 2023

Windows Secure Channel Denial of Service Vulnerability

Kerberos Polling IP Query Triggers NTLM Traffic in Microsoft Win Server
CVE-2022-47508 7.5 - High - February 15, 2023

Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.

Microsoft Windows AD Domain Services API DoS Vulnerability
CVE-2023-21816 7.5 - High - February 14, 2023

Windows Active Directory Domain Services API Denial of Service Vulnerability

Microsoft Windows Netlogon DoS via Authentication Request
CVE-2023-21728 7.5 - High - January 10, 2023

Windows Netlogon Denial of Service Vulnerability

Windows SSTP RCE Vulnerability Remote Code Execution
CVE-2022-44670 8.1 - High - December 13, 2022

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

TOCTTOU

WinServer EVP via Server Service - CVE-2022-38045
CVE-2022-38045 8.8 - High - October 11, 2022

Windows Server Service Elevation of Privilege Vulnerability

Windows Server Remote Registry Keys Info Disclosure Vulnerability
CVE-2022-38033 6.5 - Medium - October 11, 2022

Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability

Microsoft Windows GP Elevation of Privilege Vulnerability
CVE-2022-37955 7.8 - High - September 13, 2022

Windows Group Policy Elevation of Privilege Vulnerability

Microsoft Windows LDAP RCE via LDAP Server Exploit
CVE-2022-30200 7.8 - High - September 13, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Microsoft Windows Server S2D Privilege Elevation Vulnerability
CVE-2022-35792 7.8 - High - August 09, 2022

Storage Spaces Direct Elevation of Privilege Vulnerability

Windows Server Storage Spaces Direct Priv Esc Vulnerability
CVE-2022-35763 7.8 - High - August 09, 2022

Storage Spaces Direct Elevation of Privilege Vulnerability

Microsoft Windows Server ADDS Elevation of Privilege CVE-2022-34691
CVE-2022-34691 8.8 - High - August 09, 2022

Active Directory Domain Services Elevation of Privilege Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-29139 8.8 - High - May 10, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-29141 8.8 - High - May 10, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Server Service Information Disclosure Vulnerability
CVE-2022-26936 6.5 - Medium - May 10, 2022

Windows Server Service Information Disclosure Vulnerability

May 2022: Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
CVE-2022-29126 7 - High - May 10, 2022

Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability

Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-29132 7.8 - High - May 10, 2022

Windows Print Spooler Elevation of Privilege Vulnerability

Windows Clustered Shared Volume Information Disclosure Vulnerability
CVE-2022-29134 6.5 - Medium - May 10, 2022

Windows Clustered Shared Volume Information Disclosure Vulnerability

Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
CVE-2022-29135 7 - High - May 10, 2022

Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability

Windows Clustered Shared Volume Elevation of Privilege Vulnerability
CVE-2022-29138 7 - High - May 10, 2022

Windows Clustered Shared Volume Elevation of Privilege Vulnerability

Windows Print Spooler Information Disclosure Vulnerability
CVE-2022-29140 5.5 - Medium - May 10, 2022

Windows Print Spooler Information Disclosure Vulnerability

Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-29142 7 - High - May 10, 2022

Windows Kernel Elevation of Privilege Vulnerability

Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
CVE-2022-29150 7 - High - May 10, 2022

Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability

Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
CVE-2022-29151 7 - High - May 10, 2022

Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability

Windows PlayToManager Elevation of Privilege Vulnerability
CVE-2022-22016 7 - High - May 10, 2022

Windows PlayToManager Elevation of Privilege Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-22013 8.8 - High - May 10, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2022-23270 8.1 - High - May 10, 2022

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-29131 8.8 - High - May 10, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-29130 9.8 - Critical - May 10, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-29129 8.8 - High - May 10, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-29128 8.8 - High - May 10, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-22014 8.8 - High - May 10, 2022

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
CVE-2022-21972 8.1 - High - May 10, 2022

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Windows Server or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe