cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 164 of 227
CVE-2022-24490P3MEDIUMCVSS 6.5v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-24490 [MEDIUM] CVE-2022-24490: Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
nvd
CVE-2022-38042P3HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2019-1043P4MEDIUMCVSS 6.4v1803v1903+1 more2019-06-12
CVE-2019-1043 [MEDIUM] CVE-2019-1043: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2024-49082P4MEDIUMCVSS 6.8fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49082 [MEDIUM] CWE-22 CVE-2024-49082: Windows File Explorer Information Disclosure Vulnerability Windows File Explorer Information Disclosure Vulnerability
nvd
CVE-2019-1014P4HIGHCVSS 7.0v1803v1903+1 more2019-06-12
CVE-2019-1014 [HIGH] CVE-2019-1014: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vul
nvd
CVE-2019-1017P4HIGHCVSS 7.0v1803v1903+1 more2019-06-12
CVE-2019-1017 [HIGH] CVE-2019-1017: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vul
nvd
CVE-2024-21314P3MEDIUMCVSS 6.5fixed in 10.0.14393.6614≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-21314 [MEDIUM] CWE-125 CVE-2024-21314: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2025-25008P4HIGHCVSS 7.1fixed in 10.0.14393.7876≥ 10.0.14393.0, < 10.0.14393.78762025-03-11
CVE-2025-25008 [HIGH] CWE-59 CVE-2025-25008: Improper link resolution before file access ('link following') in Microsoft Windows allows an author Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-20660P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20660 [MEDIUM] CWE-125 CVE-2024-20660: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-20680P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20680 [MEDIUM] CWE-822 CVE-2024-20680: Windows Message Queuing Client (MSMQC) Information Disclosure Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
CVE-2022-21864P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21864 [HIGH] CVE-2022-21864: Windows UI Immersive Server API Elevation of Privilege Vulnerability Windows UI Immersive Server API Elevation of Privilege Vulnerability
nvd
CVE-2022-21860P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21860 [HIGH] CVE-2022-21860: Windows AppContracts API Server Elevation of Privilege Vulnerability Windows AppContracts API Server Elevation of Privilege Vulnerability
nvd
CVE-2024-20664P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20664 [MEDIUM] CWE-822 CVE-2024-20664: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2019-1126P4MEDIUMCVSS 5.3v1803v19032019-07-15
CVE-2019-1126 [MEDIUM] CVE-2019-1126: A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Director
nvd
CVE-2024-20663P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20663 [MEDIUM] CWE-822 CVE-2024-20663: Windows Message Queuing Client (MSMQC) Information Disclosure Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
CVE-2020-0875P3MEDIUMCVSS 5.5v1903v1909+2 more2020-09-11
CVE-2020-0875 [MEDIUM] CVE-2020-0875: <p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An atta An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity). This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to
nvd
CVE-2023-36706P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36706 [MEDIUM] CWE-20 CVE-2023-36706: Windows Deployment Services Information Disclosure Vulnerability Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.50062022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase