Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 171 of 227
CVE-2022-22041P4MEDIUMCVSS 6.8v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22041 [MEDIUM] CVE-2022-22041: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2024-30019P4MEDIUMCVSS 6.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30019 [MEDIUM] CWE-400 CVE-2024-30019: DHCP Server Service Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2018-0817P4HIGHCVSS 7.0v17092018-03-14
CVE-2018-0817 [HIGH] CVE-2018-0817: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows
nvd
CVE-2022-22042P4MEDIUMCVSS 6.5v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22042 [MEDIUM] CVE-2022-22042: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2018-0816P4HIGHCVSS 7.0v17092018-03-14
CVE-2018-0816 [HIGH] CVE-2018-0816: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows
nvd
CVE-2018-0868P4HIGHCVSS 7.0v17092018-03-14
CVE-2018-0868 [HIGH] CWE-20 CVE-2018-0868: Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT
Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how input is sanitized, aka "Windows Installer Elevation of Privilege
nvd
CVE-2018-0809P4HIGHCVSS 7.0v17092018-02-15
CVE-2018-0809 [HIGH] CVE-2018-0809: The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an
The Windows kernel in Windows 10, versions 1703 and 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0742, CVE-2018-0756, CVE-2018-0820 and CVE-2018-0843.
nvd
CVE-2018-0983P4HIGHCVSS 7.0v17092018-03-14
CVE-2018-0983 [HIGH] CVE-2018-0983: Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and W
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation of Privilege Vulnerability".
nvd
CVE-2022-24498P4MEDIUMCVSS 6.5v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-24498 [MEDIUM] CVE-2022-24498: Windows iSCSI Target Service Information Disclosure Vulnerability
Windows iSCSI Target Service Information Disclosure Vulnerability
nvd
CVE-2022-26816P4MEDIUMCVSS 6.5v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-26816 [MEDIUM] CVE-2022-26816: Windows DNS Server Information Disclosure Vulnerability
Windows DNS Server Information Disclosure Vulnerability
nvd
CVE-2019-0707P4HIGHCVSS 7.0v1803v19032019-05-16
CVE-2019-0707 [HIGH] CWE-787 CVE-2019-0707: An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS)
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level, aka 'Windows NDIS E
nvd
CVE-2019-0984P4HIGHCVSS 7.0v1803v1903+1 more2019-06-12
CVE-2019-0984 [HIGH] CVE-2019-0984: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2024-21356P4MEDIUMCVSS 6.5fixed in 10.0.14393.6709≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21356 [MEDIUM] CWE-476 CVE-2024-21356: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2022-22717P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.49462022-02-09
CVE-2022-22717 [HIGH] CVE-2022-22717: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-26938P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-26938 [HIGH] CVE-2022-26938: Storage Spaces Direct Elevation of Privilege Vulnerability
Storage Spaces Direct Elevation of Privilege Vulnerability
nvd
CVE-2022-21868P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21868 [HIGH] CVE-2022-21868: Windows Devices Human Interface Elevation of Privilege Vulnerability
Windows Devices Human Interface Elevation of Privilege Vulnerability
nvd
CVE-2022-21859P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21859 [HIGH] CVE-2022-21859: Windows Accounts Control Elevation of Privilege Vulnerability
Windows Accounts Control Elevation of Privilege Vulnerability
nvd
CVE-2022-29126P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29126 [HIGH] CVE-2022-29126: Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
nvd
CVE-2022-21866P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21866 [HIGH] CVE-2022-21866: Windows System Launcher Elevation of Privilege Vulnerability
Windows System Launcher Elevation of Privilege Vulnerability
nvd
CVE-2024-20657P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20657 [HIGH] CWE-284 CVE-2024-20657: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd