cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 173 of 227
CVE-2020-15706P4MEDIUMCVSS 6.4v1903v1909+1 more2020-07-29
CVE-2020-15706 [MEDIUM] CWE-362 CVE-2020-15706: GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnera GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
nvd
CVE-2025-53148P4MEDIUMCVSS 5.7fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53148 [MEDIUM] CWE-908 CVE-2025-53148: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authoriz Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-50157P4MEDIUMCVSS 5.7fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-50157 [MEDIUM] CWE-908 CVE-2025-50157: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authoriz Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-53138P4MEDIUMCVSS 5.7fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53138 [MEDIUM] CWE-908 CVE-2025-53138: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authoriz Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-53153P4MEDIUMCVSS 5.7fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53153 [MEDIUM] CWE-908 CVE-2025-53153: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authoriz Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-29956P4MEDIUMCVSS 5.4fixed in 10.0.14393.8066≥ 10.0.14393.0, < 10.0.14393.80662025-05-13
CVE-2025-29956 [MEDIUM] CWE-126 CVE-2025-29956: Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-25185P4MEDIUMCVSS 5.3fixed in 10.0.14393.8957≥ 10.0.14393.0, < 10.0.14393.89572026-03-10
CVE-2026-25185 [MEDIUM] CWE-200 CVE-2026-25185: Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows a Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-62567P4MEDIUMCVSS 5.3fixed in 10.0.14393.8688≥ 10.0.14393.0, < 10.0.14393.86882025-12-09
CVE-2025-62567 [MEDIUM] CWE-191 CVE-2025-62567: Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny serv Integer underflow (wrap or wraparound) in Windows Hyper-V allows an authorized attacker to deny service over a network.
nvd
CVE-2022-24460P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.50062022-03-09
CVE-2022-24460 [HIGH] CVE-2022-24460: Tablet Windows User Interface Application Elevation of Privilege Vulnerability Tablet Windows User Interface Application Elevation of Privilege Vulnerability
nvd
CVE-2022-29112P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29112 [MEDIUM] CVE-2022-29112: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2021-31186P4MEDIUMCVSS 6.5v20h2v1909+2 more2021-05-11
CVE-2021-31186 [MEDIUM] CVE-2021-31186: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2024-26197P4MEDIUMCVSS 6.5fixed in 10.0.14393.6796≥ 10.0.14393.0, < 10.0.14393.67962024-03-12
CVE-2024-26197 [MEDIUM] CWE-20 CVE-2024-26197: Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd
CVE-2018-8166P4HIGHCVSS 7.0v1709v18032018-05-09
CVE-2018-8166 [HIGH] CVE-2018-8166: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows
nvd
CVE-2018-8124P4HIGHCVSS 7.0v1709v18032018-05-09
CVE-2018-8124 [HIGH] CVE-2018-8124: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows
nvd
CVE-2018-1008P4HIGHCVSS 7.0v(Server Core installation)2018-04-12
CVE-2018-1008 [HIGH] CVE-2018-1008: An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windo
nvd
CVE-2019-0656P4HIGHCVSS 7.0v1709v18032019-03-05
CVE-2019-0656 [HIGH] CVE-2019-0656: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd
CVE-2018-0977P4HIGHCVSS 7.0v17092018-03-14
CVE-2018-0977 [HIGH] CVE-2018-0977: The Windows kernel mode driver in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 a The Windows kernel mode driver in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how objects are handled in memory, aka "Win32k Elevation of Privilege Vulnerability".
nvd
CVE-2018-0842P4HIGHCVSS 7.0v17092018-02-15
CVE-2018-0842 [HIGH] CVE-2018-0842: Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerability".
nvd
CVE-2020-1204P4HIGHCVSS 7.1v1903v1909+1 more2020-06-09
CVE-2020-1204 [HIGH] CVE-2020-1204: An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnosti An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'.
nvd
CVE-2023-21750P4HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21750 [HIGH] CWE-284 CVE-2023-21750: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase