Microsoft Windows Server 2016 vulnerabilities

4,167 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,167
CISA KEV
114
actively exploited
Public exploits
129
Exploited in wild
107
Severity breakdown
CRITICAL114HIGH2916MEDIUM1118LOW19

Vulnerabilities

Page 113 of 209
CVE-2022-21895HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21895 [HIGH] CWE-59 CVE-2022-21895: Windows User Profile Service Elevation of Privilege Vulnerability Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21897HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21897 [HIGH] CVE-2022-21897: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21920HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21920 [HIGH] CVE-2022-21920: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-21901HIGHCVSS 8.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21901 [HIGH] CVE-2022-21901: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2022-21860HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21860 [HIGH] CVE-2022-21860: Windows AppContracts API Server Elevation of Privilege Vulnerability Windows AppContracts API Server Elevation of Privilege Vulnerability
nvd
CVE-2022-21873HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21873 [HIGH] CVE-2022-21873: Tile Data Repository Elevation of Privilege Vulnerability Tile Data Repository Elevation of Privilege Vulnerability
nvd
CVE-2022-21881HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21881 [HIGH] CWE-362 CVE-2022-21881: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-21880HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21880 [HIGH] Windows GDI+ Information Disclosure Vulnerability Windows GDI+ Information Disclosure Vulnerability Windows GDI+ Information Disclosure Vulnerability
cvelistv5
CVE-2022-21903HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21903 [HIGH] Windows GDI Elevation of Privilege Vulnerability Windows GDI Elevation of Privilege Vulnerability Windows GDI Elevation of Privilege Vulnerability
cvelistv5
CVE-2022-21875HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21875 [HIGH] CVE-2022-21875: Windows Storage Elevation of Privilege Vulnerability Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2022-21857HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21857 [HIGH] CVE-2022-21857: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-21863HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21863 [HIGH] CVE-2022-21863: Windows StateRepository API Server file Elevation of Privilege Vulnerability Windows StateRepository API Server file Elevation of Privilege Vulnerability
nvd
CVE-2022-21910HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21910 [HIGH] CVE-2022-21910: Microsoft Cluster Port Driver Elevation of Privilege Vulnerability Microsoft Cluster Port Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-21913HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21913 [HIGH] CVE-2022-21913: Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
nvd
CVE-2022-21851HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21851 [HIGH] CVE-2022-21851: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-21883HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21919HIGHCVSS 7.0KEVPoCfixed in 10.0.14393.4886≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21919 [HIGH] CWE-59 CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21866HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21866 [HIGH] CVE-2022-21866: Windows System Launcher Elevation of Privilege Vulnerability Windows System Launcher Elevation of Privilege Vulnerability
nvd
CVE-2022-21889HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd