Back to overview

CVE-2026-44805

MEDIUM
5.5
CVSS 3.1

Metadata

CVE ID
CVE-2026-44805
State
PUBLISHED
Assigner
microsoft
Reserved
2026-05-07 20:07 UTC
Published
2026-06-09 17:06 UTC
Last updated
2026-06-10 17:55 UTC
Primary CWE
CWE-416
CWE-416: Use After Free
Vendor / Product
Microsoft / Windows Server 2019
Sources
cve.org  ·  NVD

Severity & Metrics

5.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (5)
VendorProductPlatformVersions
Microsoft Windows Server 2019 x64-based Systems 10.0.17763.0 < 10.0.17763.8880
Microsoft Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 < 10.0.17763.8880
Microsoft Windows Server 2022 x64-based Systems 10.0.20348.0 < 10.0.20348.5256
Microsoft Windows Server 2025 x64-based Systems 10.0.26100.0 < 10.0.26100.32995
Microsoft Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.32995
Weakness (CWE)
CWESourceDescription
CWE-416 cna CWE-416: Use After Free
CWE-822 cna CWE-822: Untrusted Pointer Dereference
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.5 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
References (1)
Back to overview