Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 147 of 227
CVE-2024-38126P3HIGHCVSS 7.5fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38126 [HIGH] CWE-476 CVE-2024-38126: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2025-21230P3HIGHCVSS 7.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21230 [HIGH] CWE-20 CVE-2025-21230: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21251P3HIGHCVSS 7.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21251 [HIGH] CWE-400 CVE-2025-21251: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2024-38132P3HIGHCVSS 7.5fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38132 [HIGH] CWE-125 CVE-2024-38132: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2024-38073P3HIGHCVSS 7.5fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38073 [HIGH] CWE-125 CVE-2024-38073: Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
nvd
CVE-2023-36392P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.64522023-11-14
CVE-2023-36392 [HIGH] CWE-126 CVE-2023-36392: DHCP Server Service Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2022-26932P3HIGHCVSS 8.2≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-26932 [HIGH] CVE-2022-26932: Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability
nvd
CVE-2024-38230P3HIGHCVSS 7.5fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38230 [HIGH] CWE-20 CVE-2024-38230: Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd
CVE-2023-36703P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36703 [HIGH] CWE-400 CVE-2023-36703: DHCP Server Service Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2025-21289P3HIGHCVSS 7.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21289 [HIGH] CWE-400 CVE-2025-21289: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21290P3HIGHCVSS 7.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21290 [HIGH] CWE-400 CVE-2025-21290: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21270P3HIGHCVSS 7.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21270 [HIGH] CWE-400 CVE-2025-21270: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2024-43565P3HIGHCVSS 7.5fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43565 [HIGH] CWE-125 CVE-2024-43565: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2024-43562P3HIGHCVSS 7.5fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43562 [HIGH] CWE-125 CVE-2024-43562: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2024-38072P3HIGHCVSS 7.5fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38072 [HIGH] CWE-476 CVE-2024-38072: Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
nvd
CVE-2019-0936P3HIGHCVSS 7.8v1803v19032019-05-16
CVE-2019-0936 [HIGH] CVE-2019-0936: An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly h
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0734.
nvd
CVE-2018-8471P3HIGHCVSS 7.8vWindows Server 20162018-11-14
CVE-2018-8471 [HIGH] CWE-404 CVE-2018-8471: An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU mi
An elevation of privilege vulnerability exists in the way that the Microsoft RemoteFX Virtual GPU miniport driver handles objects in memory, aka "Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 8.1, Windows 7, Windows Server 2019.
nvd
CVE-2024-38091P3HIGHCVSS 7.5fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38091 [HIGH] CWE-166 CVE-2024-38091: Microsoft WS-Discovery Denial of Service Vulnerability
Microsoft WS-Discovery Denial of Service Vulnerability
nvd
CVE-2019-1396P3HIGHCVSS 7.8v1803v19032019-11-12
CVE-2019-1396 [HIGH] CVE-2019-1396: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1395P3HIGHCVSS 7.8v1803v19032019-11-12
CVE-2019-1395 [HIGH] CVE-2019-1395: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd