Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 160 of 227
CVE-2021-33785P3HIGHCVSS 7.5v20h2v20042021-07-14
CVE-2021-33785 [HIGH] CVE-2021-33785: Windows AF_UNIX Socket Provider Denial of Service Vulnerability
Windows AF_UNIX Socket Provider Denial of Service Vulnerability
nvd
CVE-2022-21889P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-36707P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36707 [HIGH] CWE-20 CVE-2023-36707: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2022-35833P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.53562022-09-13
CVE-2022-35833 [HIGH] CVE-2022-35833: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-36585P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36585 [HIGH] CWE-20 CVE-2023-36585: Windows upnphost.dll Denial of Service Vulnerability
Windows upnphost.dll Denial of Service Vulnerability
nvd
CVE-2023-36395P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.64522023-11-14
CVE-2023-36395 [HIGH] CWE-190 CVE-2023-36395: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2023-36720P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36720 [HIGH] CVE-2023-36720: Windows Mixed Reality Developer Tools Denial of Service Vulnerability
Windows Mixed Reality Developer Tools Denial of Service Vulnerability
nvd
CVE-2022-34701P3HIGHCVSS 7.5v20h2≥ 10.0.14393.0, < 10.0.14393.52912022-08-09
CVE-2022-34701 [HIGH] CWE-400 CVE-2022-34701: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2020-1256P3MEDIUMCVSS 6.5v1903v2004+1 more2020-09-11
CVE-2020-1256 [MEDIUM] CVE-2020-1256: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2020-1097P3MEDIUMCVSS 6.5v1903v1909+2 more2020-09-11
CVE-2020-1097 [MEDIUM] CVE-2020-1097: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2022-33645P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-33645 [HIGH] CVE-2022-33645: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2023-24931P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-24931 [HIGH] CWE-125 CVE-2023-24931: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-21757P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21757 [HIGH] CWE-476 CVE-2023-21757: Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
nvd
CVE-2022-38041P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-38041 [HIGH] CVE-2022-38041: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2020-1228P3MEDIUMCVSS 6.5v1903v1909+2 more2020-09-11
CVE-2020-1228 [MEDIUM] CVE-2020-1228: <p>A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries.
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.
To exploit the vulnerability, an authenticated attacker could send malicious DNS queries to a target, resulting in a denial of service.
The update addre
nvd
CVE-2023-28241P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28241 [HIGH] CVE-2023-28241: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2020-1091P3MEDIUMCVSS 6.5v1903v1909+2 more2020-09-11
CVE-2020-1091 [MEDIUM] CVE-2020-1091: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2022-35769P3HIGHCVSS 7.5v20h2≥ 10.0.14393.0, < 10.0.14393.52912022-08-09
CVE-2022-35769 [HIGH] CWE-400 CVE-2022-35769: Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
nvd
CVE-2023-35338P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35338 [HIGH] CWE-476 CVE-2023-35338: Windows Peer Name Resolution Protocol Denial of Service Vulnerability
Windows Peer Name Resolution Protocol Denial of Service Vulnerability
nvd