cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
175
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 13 of 227
CVE-2026-21248P3HIGHCVSS 7.3PoCfixed in 10.0.14393.8868≥ 10.0.14393.0, < 10.0.14393.88682026-02-10
CVE-2026-21248 [HIGH] CWE-122 CVE-2026-21248: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2021-24093P2HIGHCVSS 8.8v20h2v1909+2 more2021-02-25
CVE-2021-24093 [HIGH] CVE-2021-24093: Windows Graphics Component Remote Code Execution Vulnerability Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2026-50518P2CRITICALCVSS 9.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50518 [CRITICAL] CWE-122 CVE-2026-50518: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-1170P3HIGHCVSS 8.8PoCv19032019-08-14
CVE-2019-1170 [HIGH] CWE-862 CVE-2019-1170: An elevation of privilege vulnerability exists when reparse points are created by sandboxed processe An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. To exploit the vulnerability, an attacker would first have to log on to the system, and then run
nvd
CVE-2022-26928P4HIGHCVSS 7.0Exploited≥ 10.0.14393.0, < 10.0.14393.57862022-09-13
CVE-2022-26928 [HIGH] CWE-362 CVE-2022-26928: Windows Photo Import API Elevation of Privilege Vulnerability Windows Photo Import API Elevation of Privilege Vulnerability
nvd
CVE-2020-0655P2HIGHCVSS 8.0v1803v1903+1 more2020-02-11
CVE-2020-0655 [HIGH] CVE-2020-0655: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Termin A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
nvd
CVE-2018-0952P3HIGHCVSS 7.8PoCv1709v1803+1 more2018-08-15
CVE-2018-0952 [HIGH] CVE-2018-0952: An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file c An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary locations, aka "Diagnostic Hub Standard Collector Elevation Of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Microsoft Visual Studio, Windows 10 Servers.
nvd
CVE-2024-38144P2HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38144 [HIGH] CWE-190 CVE-2024-38144: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-0697P2CRITICALCVSS 9.8v18032019-04-09
CVE-2019-0697 [CRITICAL] CWE-787 CVE-2019-0697: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka 'Windows DHCP Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0698, CVE-2019-0726.
nvd
CVE-2019-1182P2CRITICALCVSS 9.8v1803v1903+1 more2019-08-14
CVE-2019-1182 [CRITICAL] CVE-2019-1182: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2018-8420P2HIGHCVSS 8.8v(Server Core installation)2018-09-13
CVE-2018-8420 [HIGH] CWE-611 CVE-2018-8420: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 S
nvd
CVE-2020-1301P2HIGHCVSS 8.8v1803v1903+2 more2020-06-09
CVE-2020-1301 [HIGH] CVE-2020-1301: A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
nvd
CVE-2019-0725P2CRITICALCVSS 9.8v1803v19032019-05-16
CVE-2019-0725 [CRITICAL] CWE-787 CVE-2019-0725: A memory corruption vulnerability exists in the Windows Server DHCP service when processing speciall A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
nvd
CVE-2025-49683P3HIGHCVSS 7.8PoCfixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49683 [HIGH] CWE-122 CVE-2025-49683: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execut Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-49160P2HIGHCVSS 7.5fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-49160 [HIGH] CWE-400 CVE-2026-49160: Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a n Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-60724P2CRITICALCVSS 9.8fixed in 10.0.14393.8594≥ 10.0.14393.0, < 10.0.14393.85942025-11-11
CVE-2025-60724 [CRITICAL] CWE-122 CVE-2025-60724: Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execut Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-0552P3HIGHCVSS 8.8PoCv1709v1803+1 more2019-01-08
CVE-2019-0552 [HIGH] CWE-863 CVE-2019-0552: An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privil An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2019-1089P3HIGHCVSS 7.8PoCv1803v19032019-07-15
CVE-2019-1089 [HIGH] CVE-2019-1089: An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel i An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. To exploit this vulnerability, a low level authenticated attacker could run a specially crafted application. The security update addresses this vulnerability by correcting how rpcss.dll handles these requests., aka 'Windows RPCSS
nvd
CVE-2019-0732P3HIGHCVSS 7.8PoCv1709v18032019-04-09
CVE-2019-0732 [HIGH] CWE-863 CVE-2019-0732: A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass De A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.
nvd
CVE-2018-0749P3HIGHCVSS 7.8PoCv17092018-01-04
CVE-2018-0749 [HIGH] CVE-2018-0749: The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Se The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way SMB Server handles specially crafted files, aka "W
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase