| Windows Server | Number Of NVD | 5091 | CRITICAL | 122 | HIGH | 3461 | MEDIUM | 1438 | LOW | 70 |
| URL | https://www.microsoft.com/ | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Explanation | Server products offered by Microsoft. For business, developer, and desktop operating system products, 10 years of support at the supported Service Pack level (with a minimum of 5 years of mainstream support, followed by a minimum of 5 years of extended support). You may need to deploy the latest updates to be eligible for support. For some products, the support organization may be less than 10 years. For consumer and multimedia products, five years of mainstream support at the supported Service Pack level. The above text is excerpted from Microsoft's Fixed Lifecycle Policy. |
||||||||
| Tag | |||||||||
| No | Type | Name | URL |
|---|---|---|---|
| 1 | https://support.microsoft.com//lifecycle/search | ||
| 2 | https://www.microsoft.com/ja-jp/cloud-platform/windows-server | ||
| 3 | https://support.microsoft.com/ja-jp/hub/4095338/microsoft-lifecycle-policy | ||
| 4 | https://docs.microsoft.com/ja-jp/windows-server/get-started/windows-server-release-info |
| No | Name | Latest Version | Release date | Initial release | Normal Support | Security Support Service Pack Support |
Extended for a fee |
Critical | High | Medium | Low |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Windows Server 2022 | 21H2 | Nov. 2, 2021 | Nov. 2, 2021 | Oct. 13, 2026 | Oct. 14, 2031 | 53 | 1279 | 421 | 5 | |
| 2 | Windows Server 2019 | 1809 | Oct. 2, 2018 | Nov. 13, 2018 | Jan. 9, 2024 | Jan. 9, 2029 | 94 | 2460 | 885 | 11 | |
| 3 | Windows Server 2016 | 20H2 | Oct. 20, 2020 | Oct. 15, 2016 | Jan. 11, 2022 | Jan. 12, 2027 | 103 | 2553 | 1010 | 15 | |
| 4 | Windows Server 2012 | Oct. 30, 2012 | Oct. 30, 2012 | Oct. 9, 2018 | Oct. 10, 2023 | 94 | 2178 | 911 | 50 | ||
| 5 | Windows Server 2008 R2( Service Pack 1適用) | Feb. 22, 2011 | Jan. 14, 2020 | 0 | 0 | 0 | 0 | ||||
| 6 | Windows Server 2008(Service Pack 2適用) | April 29, 2009 | Jan. 14, 2020 | 0 | 0 | 0 | 0 | ||||
| 7 | Microsoft Windows Server 2003(Service Pack 2適用) | May 28, 2003 | July 13, 2010 | July 14, 2015 | 0 | 128 | 53 | 15 | |||
| 8 | Microsoft Windows Storage Server 2003 | May 5, 2003 | Oct. 11, 2011 | Oct. 9, 2016 | 0 | 128 | 53 | 15 | |||
| 9 | Microsoft Windows 2000(Service Pack 4適用) | March 31, 2000 | June 30, 2005 | July 13, 2010 | 2 | 40 | 19 | 0 |
| No | CVSS3 CVSS2 |
Level Attach Vector |
Title | CWE | CVE | cpe23Uri | or higher | or less | more than | less than | Update date Published date |
Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 |
4.3 - |
MEDIUM
Network |
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. |
CWE-200
Information Exposure |
CVE-2026-33829 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8644 10.0.14393.9060 |
2026-04-21 23:16 2026-04-15 |
Show | GitHub Exploit DB Packet Storm |
| 2 |
7.0 - |
HIGH
Local |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. |
CWE-362 CWE-416 Race Condition Use After Free |
CVE-2026-33104 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8644 10.0.14393.9060 |
2026-04-18 03:20 2026-04-15 |
Show | GitHub Exploit DB Packet Storm |
| 3 |
5.5 - |
MEDIUM
Local |
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2026-32217 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8644 10.0.14393.9060 |
2026-04-20 23:34 2026-04-15 |
Show | GitHub Exploit DB Packet Storm |
| 4 |
5.5 - |
MEDIUM
Local |
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. |
CWE-532
Inclusion of Sensitive Information in Log Files |
CVE-2026-32215 | cpe:2.3:o:microsoft:windows_server_2019:*:* | 10.0.17763.8644 |
2026-04-20 23:35 2026-04-15 |
Show | GitHub Exploit DB Packet Storm | |||
| 5 |
5.5 - |
MEDIUM
Local |
Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. |
CWE-284
Improper Access Control |
CVE-2026-32214 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8644 10.0.14393.9060 |
2026-04-20 23:43 2026-04-15 |
Show | GitHub Exploit DB Packet Storm |
| 6 |
5.5 - |
MEDIUM
Local |
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. |
CWE-59 CWE-269 Link Following Improper Privilege Management |
CVE-2026-32212 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8644 10.0.14393.9060 |
2026-04-20 23:55 2026-04-15 |
Show | GitHub Exploit DB Packet Storm |
| 7 |
4.3 - |
MEDIUM
Network |
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. |
CWE-693
Protection Mechanism Failure |
CVE-2026-32202 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8644 10.0.14393.9060 |
2026-04-21 00:32 2026-04-15 |
Show | GitHub Exploit DB Packet Storm |
| 8 |
7.8 - |
HIGH
Local |
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally. |
CWE-77
Command Injection |
CVE-2026-32183 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* cpe:2.3:o:microsoft:windo… |
|
|
|
10.0.17763.8644 10.0.14393.9060 |
2026-04-21 01:40 2026-04-15 |
Show | GitHub Exploit DB Packet Storm |
| 9 |
7.8 - |
HIGH
Local |
Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally. |
CWE-362 CWE-416 Race Condition Use After Free |
CVE-2026-32165 | cpe:2.3:o:microsoft:windows_server_2019:*:* | 10.0.17763.8644 |
2026-04-21 01:42 2026-04-15 |
Show | GitHub Exploit DB Packet Storm | |||
| 10 |
7.8 - |
HIGH
Local |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally. |
CWE-362
Race Condition |
CVE-2026-32164 |
cpe:2.3:o:microsoft:windows_server_2019:*:* cpe:2.3:o:microsoft:windows_server_2016:*:* |
|
|
|
10.0.17763.8644 10.0.14393.9060 |
2026-04-21 01:43 2026-04-15 |
Show | GitHub Exploit DB Packet Storm |