Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 167 of 227
CVE-2026-49804P3MEDIUMCVSS 6.6fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-49804 [MEDIUM] CWE-122 CVE-2026-49804: Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate pr
Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2020-1397P4MEDIUMCVSS 6.5v1903v1909+1 more2020-07-14
CVE-2020-1397 [MEDIUM] CVE-2020-1397: An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails t
An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.
nvd
CVE-2020-0880P4MEDIUMCVSS 6.5v1803v1903+1 more2020-03-12
CVE-2020-0880 [MEDIUM] CVE-2020-0880: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2020-0882.
nvd
CVE-2020-0882P4MEDIUMCVSS 6.5v1803v1903+1 more2020-03-12
CVE-2020-0882 [MEDIUM] CVE-2020-0882: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0874, CVE-2020-0879, CVE-2020-0880.
nvd
CVE-2018-8422P4MEDIUMCVSS 6.5v(Server Core installation)2018-09-13
CVE-2018-8422 [MEDIUM] CWE-200 CVE-2018-8422: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.
nvd
CVE-2020-1179P4MEDIUMCVSS 6.5v1803v1903+1 more2020-05-21
CVE-2020-1179 [MEDIUM] CVE-2020-1179: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0963, CVE-2020-1141, CVE-2020-1145.
nvd
CVE-2019-0712P4MEDIUMCVSS 6.8v1803v19032019-11-12
CVE-2019-0712 [MEDIUM] CWE-20 CVE-2019-0712: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309, CVE-2019-1310, CVE-2019-1399.
nvd
CVE-2019-1309P4MEDIUMCVSS 6.8v1803v19032019-11-12
CVE-2019-1309 [MEDIUM] CVE-2019-1309: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1310, CVE-2019-1399.
nvd
CVE-2019-1310P4MEDIUMCVSS 6.8v1803v19032019-11-12
CVE-2019-1310 [MEDIUM] CVE-2019-1310: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1399.
nvd
CVE-2020-1232P4MEDIUMCVSS 6.5v1803v1903+2 more2020-06-09
CVE-2020-1232 [MEDIUM] CWE-125 CVE-2020-1232: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m
An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.
nvd
CVE-2020-0952P4MEDIUMCVSS 6.5v1803v1903+1 more2020-04-15
CVE-2020-0952 [MEDIUM] CVE-2020-0952: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2020-0963P4MEDIUMCVSS 6.5v1803v1903+1 more2020-05-21
CVE-2020-0963 [MEDIUM] CVE-2020-0963: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1141, CVE-2020-1145, CVE-2020-1179.
nvd
CVE-2026-50324P4MEDIUMCVSS 5.9fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50324 [MEDIUM] CWE-835 CVE-2026-50324: Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD F
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2020-1348P4MEDIUMCVSS 6.5v1803v1903+2 more2020-06-09
CVE-2020-1348 [MEDIUM] CVE-2020-1348: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2020-1468P4MEDIUMCVSS 6.5v1903v1909+1 more2020-07-14
CVE-2020-1468 [MEDIUM] CVE-2020-1468: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-1411P4MEDIUMCVSS 6.5v1803v19032019-11-12
CVE-2019-1411 [MEDIUM] CWE-125 CVE-2019-1411: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.
nvd
CVE-2020-0837P4MEDIUMCVSS 5.3v1903v1909+2 more2020-09-11
CVE-2020-0837 [MEDIUM] CVE-2020-0837: <p>An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) i
An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication factors.
To exploit this vulnerability, an attacker could send a specially crafted authenticatio
nvd
CVE-2019-0717P4MEDIUMCVSS 5.8v19032019-08-14
CVE-2019-0717 [MEDIUM] CWE-20 CVE-2019-0717: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0718P4MEDIUMCVSS 5.8v1803v1903+1 more2019-08-14
CVE-2019-0718 [MEDIUM] CWE-20 CVE-2019-0718: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0723P4MEDIUMCVSS 5.8v1803v1903+1 more2019-08-14
CVE-2019-0723 [MEDIUM] CWE-20 CVE-2019-0723: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash.
To exploit the vulnerability, an attacker who already has a privileged account
nvd