Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 101 of 227
CVE-2024-38066P3HIGHCVSS 7.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38066 [HIGH] CWE-416 CVE-2024-38066: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2023-21747P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21747 [HIGH] CWE-416 CVE-2023-21747: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-1245P3HIGHCVSS 7.8v1903v1909+2 more2020-09-11
CVE-2020-1245 [HIGH] CVE-2020-1245: <p>An elevation of privilege vulnerability exists in Windows when the Win32k component fails to prop
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2023-21675P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21675 [HIGH] CWE-843 CVE-2023-21675: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21748P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21748 [HIGH] CVE-2023-21748: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21749P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21749 [HIGH] CWE-20 CVE-2023-21749: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-21373P3HIGHCVSS 7.8fixed in 10.0.14393.7785≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21373 [HIGH] CWE-59 CVE-2025-21373: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1272P3HIGHCVSS 7.8v1803v1903+2 more2020-06-09
CVE-2020-1272 [HIGH] CVE-2020-1272: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE
nvd
CVE-2024-38034P3HIGHCVSS 7.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38034 [HIGH] CWE-190 CVE-2024-38034: Windows Filtering Platform Elevation of Privilege Vulnerability
Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-23420P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-23420 [HIGH] CWE-416 CVE-2023-23420: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2020-1431P3HIGHCVSS 7.8v1903v1909+1 more2020-07-14
CVE-2020-1431 [HIGH] CWE-269 CVE-2020-1431: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correc
nvd
CVE-2020-1553P3HIGHCVSS 7.8v1903v1909+2 more2020-08-17
CVE-2020-1553 [HIGH] CVE-2020-1553: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
The update addresses the vulnerabili
nvd
CVE-2023-28248P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28248 [HIGH] CWE-190 CVE-2023-28248: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-21436P3HIGHCVSS 7.8fixed in 10.0.14393.6796≥ 10.0.14393.0, < 10.0.14393.67962024-03-12
CVE-2024-21436 [HIGH] CWE-284 CVE-2024-21436: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1159P3HIGHCVSS 7.8v1903v1909+1 more2020-09-11
CVE-2020-1159 [HIGH] CVE-2020-1159: <p>An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file
An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update add
nvd
CVE-2023-21774P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21774 [HIGH] CWE-416 CVE-2023-21774: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21772P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21772 [HIGH] CWE-125 CVE-2023-21772: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-22043P3HIGHCVSS 7.8v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22043 [HIGH] CVE-2022-22043: Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-20658P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20658 [HIGH] CWE-125 CVE-2024-20658: Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
nvd
CVE-2023-21773P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21773 [HIGH] CWE-416 CVE-2023-21773: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd