Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 164 of 227
CVE-2022-24490P3MEDIUMCVSS 6.5v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-24490 [MEDIUM] CVE-2022-24490: Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
nvd
CVE-2022-38042P3HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability
Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2019-1043P4MEDIUMCVSS 6.4v1803v1903+1 more2019-06-12
CVE-2019-1043 [MEDIUM] CVE-2019-1043: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory.
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2024-49082P4MEDIUMCVSS 6.8fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49082 [MEDIUM] CWE-22 CVE-2024-49082: Windows File Explorer Information Disclosure Vulnerability
Windows File Explorer Information Disclosure Vulnerability
nvd
CVE-2019-1014P4HIGHCVSS 7.0v1803v1903+1 more2019-06-12
CVE-2019-1014 [HIGH] CVE-2019-1014: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2019-1017P4HIGHCVSS 7.0v1803v1903+1 more2019-06-12
CVE-2019-1017 [HIGH] CVE-2019-1017: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd
CVE-2024-21314P3MEDIUMCVSS 6.5fixed in 10.0.14393.6614≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-21314 [MEDIUM] CWE-125 CVE-2024-21314: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2025-25008P4HIGHCVSS 7.1fixed in 10.0.14393.7876≥ 10.0.14393.0, < 10.0.14393.78762025-03-11
CVE-2025-25008 [HIGH] CWE-59 CVE-2025-25008: Improper link resolution before file access ('link following') in Microsoft Windows allows an author
Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-20660P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20660 [MEDIUM] CWE-125 CVE-2024-20660: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2024-20680P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20680 [MEDIUM] CWE-822 CVE-2024-20680: Windows Message Queuing Client (MSMQC) Information Disclosure
Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
CVE-2022-21864P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21864 [HIGH] CVE-2022-21864: Windows UI Immersive Server API Elevation of Privilege Vulnerability
Windows UI Immersive Server API Elevation of Privilege Vulnerability
nvd
CVE-2022-21860P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21860 [HIGH] CVE-2022-21860: Windows AppContracts API Server Elevation of Privilege Vulnerability
Windows AppContracts API Server Elevation of Privilege Vulnerability
nvd
CVE-2024-20664P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20664 [MEDIUM] CWE-822 CVE-2024-20664: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2019-1126P4MEDIUMCVSS 5.3v1803v19032019-07-15
CVE-2019-1126 [MEDIUM] CVE-2019-1126: A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which
A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Director
nvd
CVE-2024-20663P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20663 [MEDIUM] CWE-822 CVE-2024-20663: Windows Message Queuing Client (MSMQC) Information Disclosure
Windows Message Queuing Client (MSMQC) Information Disclosure
nvd
CVE-2020-0875P3MEDIUMCVSS 5.5v1903v1909+2 more2020-09-11
CVE-2020-0875 [MEDIUM] CVE-2020-0875: <p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An atta
An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity).
This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to
nvd
CVE-2023-36706P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36706 [MEDIUM] CWE-20 CVE-2023-36706: Windows Deployment Services Information Disclosure Vulnerability
Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.50062022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability
Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd