Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 165 of 227
CVE-2024-38022P4HIGHCVSS 7.0fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38022 [HIGH] CWE-59 CVE-2024-38022: Windows Image Acquisition Elevation of Privilege Vulnerability
Windows Image Acquisition Elevation of Privilege Vulnerability
nvd
CVE-2023-36403P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.64522023-11-14
CVE-2023-36403 [HIGH] CWE-591 CVE-2023-36403: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43535P4HIGHCVSS 7.0fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43535 [HIGH] CWE-416 CVE-2024-43535: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43570P4HIGHCVSS 7.0fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43570 [HIGH] CWE-416 CVE-2024-43570: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2026-49165P4HIGHCVSS 7.1fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-49165 [HIGH] CWE-908 CVE-2026-49165: Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclo
Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.
nvd
CVE-2024-49084P4HIGHCVSS 7.0fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49084 [HIGH] CWE-362 CVE-2024-49084: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43511P4HIGHCVSS 7.0fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.75152024-10-08
CVE-2024-43511 [HIGH] CWE-367 CVE-2024-43511: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-29364P4HIGHCVSS 7.0fixed in 10.0.14393.5989≥ 10.0.14393.0, < 10.0.14393.59892023-06-14
CVE-2023-29364 [HIGH] CWE-190 CVE-2023-29364: Windows Authentication Elevation of Privilege Vulnerability
Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2024-38069P4HIGHCVSS 7.0fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38069 [HIGH] CWE-347 CVE-2024-38069: Windows Enroll Engine Security Feature Bypass Vulnerability
Windows Enroll Engine Security Feature Bypass Vulnerability
nvd
CVE-2025-21191P4HIGHCVSS 7.0fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-21191 [HIGH] CWE-367 CVE-2025-21191: Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows a
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-38033P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-38033 [MEDIUM] CVE-2022-38033: Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
nvd
CVE-2025-21301P4MEDIUMCVSS 6.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21301 [MEDIUM] CWE-284 CVE-2025-21301: Windows Geolocation Service Information Disclosure Vulnerability
Windows Geolocation Service Information Disclosure Vulnerability
nvd
CVE-2023-24865P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24865 [MEDIUM] CWE-20 CVE-2023-24865: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24866P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24866 [MEDIUM] CWE-20 CVE-2023-24866: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-35296P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35296 [MEDIUM] CWE-125 CVE-2023-35296: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2026-26152P4HIGHCVSS 7.0fixed in 10.0.14393.9060≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-26152 [HIGH] CWE-922 CVE-2026-26152: Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized att
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27468P4HIGHCVSS 7.0fixed in 10.0.14393.8066≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-27468 [HIGH] CWE-269 CVE-2025-27468: Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-34301P4MEDIUMCVSS 6.7v20h22022-08-26
CVE-2022-34301 [MEDIUM] CVE-2022-34301: A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bo
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Pa
nvd
CVE-2022-41097P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.55012022-11-09
CVE-2022-41097 [MEDIUM] CVE-2022-41097: Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
nvd
CVE-2023-35316P3MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35316 [MEDIUM] CWE-125 CVE-2023-35316: Remote Procedure Call Runtime Information Disclosure Vulnerability
Remote Procedure Call Runtime Information Disclosure Vulnerability
nvd