Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 169 of 227
CVE-2023-36405P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.64522023-11-14
CVE-2023-36405 [HIGH] CWE-362 CVE-2023-36405: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26242P4HIGHCVSS 7.0fixed in 10.0.14393.6897≥ 10.0.14393.0, < 10.0.14393.68972024-04-09
CVE-2024-26242 [HIGH] CWE-591 CVE-2024-26242: Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2022-34302P4MEDIUMCVSS 6.7v20h22022-08-26
CVE-2022-34302 [MEDIUM] CVE-2022-34302: A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this boot
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Part
nvd
CVE-2023-35361P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35361 [HIGH] CWE-362 CVE-2023-35361: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-35360P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35360 [HIGH] CWE-591 CVE-2023-35360: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2018-0753P4MEDIUMCVSS 5.9v17092018-01-04
CVE-2018-0753 [MEDIUM] CVE-2018-0753: Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wind
Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow a denial of service vulnerability due to the way objects are handled in memory, aka "Windows IPSec Denial of Service Vulnerability".
nvd
CVE-2024-30063P4MEDIUMCVSS 6.7fixed in 10.0.14393.7070≥ 10.0.14393.0, < 10.0.14393.70702024-06-11
CVE-2024-30063 [MEDIUM] CWE-641 CVE-2024-30063: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2025-49678P4HIGHCVSS 7.0fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49678 [HIGH] CWE-362 CVE-2025-49678: Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-24883P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-24883 [MEDIUM] CWE-126 CVE-2023-24883: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24906P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24906 [MEDIUM] CWE-190 CVE-2023-24906: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24857P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24857 [MEDIUM] CWE-126 CVE-2023-24857: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24863P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24863 [MEDIUM] CWE-190 CVE-2023-24863: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24870P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-24870 [MEDIUM] CWE-126 CVE-2023-24870: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2026-45658P4MEDIUMCVSS 6.8fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45658 [MEDIUM] CWE-284 CVE-2026-45658: Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feat
Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50298P4MEDIUMCVSS 6.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50298 [MEDIUM] CWE-190 CVE-2026-50298: Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate p
Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50299P4MEDIUMCVSS 6.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50299 [MEDIUM] CWE-122 CVE-2026-50299: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e
Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-57097P4MEDIUMCVSS 6.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-57097 [MEDIUM] CWE-426 CVE-2026-57097: Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature
Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48807P4MEDIUMCVSS 6.7fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.84222025-08-12
CVE-2025-48807 [MEDIUM] CWE-923 CVE-2025-48807: Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an aut
Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
nvd
CVE-2020-1284P4MEDIUMCVSS 6.5v20042020-06-09
CVE-2020-1284 [MEDIUM] CVE-2020-1284: A denial of service vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (S
A denial of service vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Denial of Service Vulnerability'.
nvd
CVE-2026-32170P4MEDIUMCVSS 6.7fixed in 10.0.14393.9140≥ 10.0.14393.0, < 10.0.14393.91402026-05-12
CVE-2026-32170 [MEDIUM] CWE-415 CVE-2026-32170: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd