Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 111 of 227
CVE-2021-1655P3HIGHCVSS 7.8v20h2v1909+2 more2021-01-12
CVE-2021-1655 [HIGH] CWE-269 CVE-2021-1655: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2020-17137P3HIGHCVSS 7.8v20h2v20042020-12-10
CVE-2020-17137 [HIGH] CVE-2020-17137: DirectX Graphics Kernel Elevation of Privilege Vulnerability
DirectX Graphics Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-27741P3HIGHCVSS 7.8fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27741 [HIGH] CWE-125 CVE-2025-27741: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-21822P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21822 [HIGH] CWE-416 CVE-2023-21822: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2020-1396P3HIGHCVSS 7.8v1903v1909+1 more2020-07-14
CVE-2020-1396 [HIGH] CVE-2020-1396: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Windows ALPC Elevation of Privilege Vulnerability'.
nvd
CVE-2023-36726P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36726 [HIGH] CWE-416 CVE-2023-36726: Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
nvd
CVE-2020-0844P3HIGHCVSS 7.8v1803v1903+1 more2020-03-12
CVE-2020-0844 [HIGH] CVE-2020-0844: An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service
An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'.
nvd
CVE-2021-26891P3HIGHCVSS 7.8v20h2v1909+2 more2021-03-11
CVE-2021-26891 [HIGH] CVE-2021-26891: Windows Container Execution Agent Elevation of Privilege Vulnerability
Windows Container Execution Agent Elevation of Privilege Vulnerability
nvd
CVE-2022-34711P3HIGHCVSS 7.8v20h2≥ 10.0.14393.0, < 10.0.14393.52912022-08-15
CVE-2022-34711 [HIGH] CVE-2022-34711: Windows Defender Credential Guard Elevation of Privilege Vulnerability
Windows Defender Credential Guard Elevation of Privilege Vulnerability
nvd
CVE-2021-33751P3HIGHCVSS 7.8v20h2v2004+1 more2021-07-14
CVE-2021-33751 [HIGH] CWE-269 CVE-2021-33751: Storage Spaces Controller Elevation of Privilege Vulnerability
Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2023-21805P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21805 [HIGH] CWE-77 CVE-2023-21805: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2025-27483P3HIGHCVSS 7.8fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27483 [HIGH] CWE-125 CVE-2025-27483: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-29367P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.59892023-06-14
CVE-2023-29367 [HIGH] CWE-908 CVE-2023-29367: iSCSI Target WMI Provider Remote Code Execution Vulnerability
iSCSI Target WMI Provider Remote Code Execution Vulnerability
nvd
CVE-2022-22031P3HIGHCVSS 7.8v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22031 [HIGH] CWE-312 CVE-2022-22031: Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability
Windows Credential Guard Domain-joined Public Key Elevation of Privilege Vulnerability
nvd
CVE-2025-27733P3HIGHCVSS 7.8fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27733 [HIGH] CWE-125 CVE-2025-27733: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2021-41347P3HIGHCVSS 7.8v20h2v2004+1 more2021-10-13
CVE-2021-41347 [HIGH] CWE-269 CVE-2021-41347: Windows AppX Deployment Service Elevation of Privilege Vulnerability
Windows AppX Deployment Service Elevation of Privilege Vulnerability
nvd
CVE-2021-31951P3HIGHCVSS 7.8v20h2v20042021-06-08
CVE-2021-31951 [HIGH] CVE-2021-31951: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2021-1689P3HIGHCVSS 7.8v20h2v1909+2 more2021-01-12
CVE-2021-1689 [HIGH] CWE-269 CVE-2021-1689: Windows Multipoint Management Elevation of Privilege Vulnerability
Windows Multipoint Management Elevation of Privilege Vulnerability
nvd
CVE-2022-21873P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21873 [HIGH] CVE-2022-21873: Tile Data Repository Elevation of Privilege Vulnerability
Tile Data Repository Elevation of Privilege Vulnerability
nvd
CVE-2023-21691P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21691 [HIGH] CWE-125 CVE-2023-21691: Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability
nvd