cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 161 of 227
CVE-2023-32011P3HIGHCVSS 7.5fixed in 10.0.14393.5989≥ 10.0.14393.0, < 10.0.14393.59892023-06-14
CVE-2023-32011 [HIGH] CWE-125 CVE-2023-32011: Windows iSCSI Discovery Service Denial of Service Vulnerability Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-28217P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28217 [HIGH] CWE-400 CVE-2023-28217: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2022-41058P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.55012022-11-09
CVE-2022-41058 [HIGH] CVE-2022-41058: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2023-36912P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.61672023-08-08
CVE-2023-36912 [HIGH] CWE-20 CVE-2023-36912: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2018-8304P3MEDIUMCVSS 5.9v1709v(Server Core installation)2018-07-11
CVE-2018-8304 [MEDIUM] CVE-2018-8304: A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fail A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows
nvd
CVE-2023-38172P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.61672023-08-08
CVE-2023-38172 [HIGH] CWE-126 CVE-2023-38172: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-24859P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24859 [HIGH] CWE-476 CVE-2023-24859: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21813P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21813 [HIGH] CWE-126 CVE-2023-21813: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-32044P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-32044 [HIGH] CWE-125 CVE-2023-32044: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-32045P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-32045 [HIGH] CWE-125 CVE-2023-32045: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2018-8308P3MEDIUMCVSS 6.6v1709v1803+1 more2018-07-11
CVE-2018-8308 [MEDIUM] CWE-404 CVE-2018-8308: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Win
nvd
CVE-2020-16997P4MEDIUMCVSS 6.5v20h2v1903+3 more2020-11-11
CVE-2020-16997 [MEDIUM] CVE-2020-16997: Remote Desktop Protocol Server Information Disclosure Vulnerability Remote Desktop Protocol Server Information Disclosure Vulnerability
nvd
CVE-2020-1487P3MEDIUMCVSS 6.5v1903v1909+2 more2020-08-17
CVE-2020-1487 [MEDIUM] CVE-2020-1487: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log onto an affected system and open a specially crafted file. In a web-b
nvd
CVE-2023-36805P4HIGHCVSS 7.0fixed in 10.0.14393.6252≥ 10.0.14393.0, < 10.0.14393.62522023-09-12
CVE-2023-36805 [HIGH] CWE-77 CVE-2023-36805: Windows MSHTML Platform Security Feature Bypass Vulnerability Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2021-43216P3MEDIUMCVSS 6.5v2004≥ 10.0.0, < 10.0.14393.48252021-12-15
CVE-2021-43216 [MEDIUM] CWE-668 CVE-2021-43216: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2019-1185P3HIGHCVSS 7.3v19032019-08-14
CVE-2019-1185 [HIGH] CWE-121 CVE-2019-1185: An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Li An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnera
nvd
CVE-2021-43237P3HIGHCVSS 7.3v20042021-12-15
CVE-2021-43237 [HIGH] CWE-59 CVE-2021-43237: Windows Setup Elevation of Privilege Vulnerability Windows Setup Elevation of Privilege Vulnerability
nvd
CVE-2022-35822P3HIGHCVSS 7.1v20h2≥ 10.0.14393.0, < 10.0.14393.52912022-08-15
CVE-2022-35822 [HIGH] CVE-2022-35822: Windows Defender Credential Guard Security Feature Bypass Vulnerability Windows Defender Credential Guard Security Feature Bypass Vulnerability
nvd
CVE-2024-30036P3MEDIUMCVSS 6.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30036 [MEDIUM] CWE-41 CVE-2024-30036: Windows Deployment Services Information Disclosure Vulnerability Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2019-1018P4HIGHCVSS 7.0v1803≥ 10.0.14393.0, < publication2019-06-12
CVE-2019-1018 [HIGH] CVE-2019-1018: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase