cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 120 of 227
CVE-2020-1133P3HIGHCVSS 7.8v1903v1909+2 more2020-09-11
CVE-2020-1133 [HIGH] CVE-2020-1133: <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improp An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the
nvd
CVE-2020-17024P3HIGHCVSS 7.8v20h2v1903+3 more2020-11-11
CVE-2020-17024 [HIGH] CVE-2020-17024: Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability
nvd
CVE-2020-17041P3HIGHCVSS 7.8v20h2v1903+3 more2020-11-11
CVE-2020-17041 [HIGH] CVE-2020-17041: Windows Print Configuration Elevation of Privilege Vulnerability Windows Print Configuration Elevation of Privilege Vulnerability
nvd
CVE-2019-1319P3HIGHCVSS 7.8v1803v19032019-10-10
CVE-2019-1319 [HIGH] CVE-2019-1319: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0648P3HIGHCVSS 7.8v1903v1909+2 more2020-09-11
CVE-2020-0648 [HIGH] CVE-2020-0648: <p>An elevation of privilege vulnerability exists when the Windows RSoP Service Application improper An elevation of privilege vulnerability exists when the Windows RSoP Service Application improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how
nvd
CVE-2022-24499P3HIGHCVSS 7.8v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-24499 [HIGH] CVE-2022-24499: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-0764P3HIGHCVSS 7.8v1903v1909+2 more2020-10-16
CVE-2020-0764 [HIGH] CVE-2020-0764: <p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handl An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a specially crafted application. The
nvd
CVE-2020-1122P3HIGHCVSS 7.8v1903v1909+1 more2020-09-11
CVE-2020-1122 [HIGH] CWE-754 CVE-2020-1122: <p>An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperl An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresse
nvd
CVE-2020-0776P3HIGHCVSS 7.8v1803v1903+1 more2020-03-12
CVE-2020-0776 [HIGH] CVE-2020-0776: An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly ha An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0858.
nvd
CVE-2020-0769P3HIGHCVSS 7.8v1803v1903+1 more2020-03-12
CVE-2020-0769 [HIGH] CVE-2020-0769: An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memor An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0771.
nvd
CVE-2020-1527P3HIGHCVSS 7.8v1903v1909+2 more2020-08-17
CVE-2020-1527 [HIGH] CVE-2020-1527: An elevation of privilege vulnerability exists when the Windows Custom Protocol Engine improperly ha An elevation of privilege vulnerability exists when the Windows Custom Protocol Engine improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how t
nvd
CVE-2020-17077P3HIGHCVSS 7.8v20h2v1903+2 more2020-11-11
CVE-2020-17077 [HIGH] CVE-2020-17077: Windows Update Stack Elevation of Privilege Vulnerability Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2021-34483P3HIGHCVSS 7.8v20h2v2004+1 more2021-08-12
CVE-2021-34483 [HIGH] CWE-269 CVE-2021-34483: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-34537P3HIGHCVSS 8.0v20h2v2004+1 more2021-08-12
CVE-2021-34537 [HIGH] CWE-269 CVE-2021-34537: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-1559P3HIGHCVSS 7.8v1903v1909+2 more2020-09-11
CVE-2020-1559 [HIGH] CVE-2020-1559: <p>An elevation of privilege vulnerability exists when the Windows Storage Services improperly handl An elevation of privilege vulnerability exists when the Windows Storage Services improperly handle file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a specially crafted application. The
nvd
CVE-2020-1532P3HIGHCVSS 7.8v1903v1909+1 more2020-09-11
CVE-2020-1532 [HIGH] CVE-2020-1532: <p>An elevation of privilege vulnerability exists when the Windows InstallService improperly handles An elevation of privilege vulnerability exists when the Windows InstallService improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how the Windo
nvd
CVE-2020-1556P3HIGHCVSS 7.8v1903v1909+2 more2020-08-17
CVE-2020-1556 [HIGH] CVE-2020-1556: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vuln
nvd
CVE-2021-1685P3HIGHCVSS 7.8v20h2v1909+2 more2021-01-12
CVE-2021-1685 [HIGH] CWE-269 CVE-2021-1685: Windows AppX Deployment Extensions Elevation of Privilege Vulnerability Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
nvd
CVE-2020-16976P3HIGHCVSS 7.8v1903v1909+2 more2020-10-16
CVE-2020-16976 [HIGH] CVE-2020-16976: <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting ho
nvd
CVE-2020-16876P3HIGHCVSS 7.8v1903v1909+2 more2020-10-16
CVE-2020-16876 [HIGH] CVE-2020-16876: <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a spec
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase