Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 174 of 227
CVE-2023-28222P4HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28222 [HIGH] CWE-59 CVE-2023-28222: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-0931P4HIGHCVSS 7.0v1803v19032019-05-16
CVE-2019-0931 [HIGH] CVE-2019-0931: An elevation of privilege vulnerability exists when the Storage Service improperly handles file oper
An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'.
nvd
CVE-2023-28267P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28267 [MEDIUM] CWE-126 CVE-2023-28267: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2019-1180P4HIGHCVSS 7.0v1803v1903+1 more2019-08-14
CVE-2019-1180 [HIGH] CVE-2019-1180: An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in mem
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability b
nvd
CVE-2019-1178P4HIGHCVSS 7.0v1803v1903+1 more2019-08-14
CVE-2019-1178 [HIGH] CVE-2019-1178: An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in me
An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability
nvd
CVE-2019-1179P4HIGHCVSS 7.0v1803v1903+1 more2019-08-14
CVE-2019-1179 [HIGH] CVE-2019-1179: An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in m
An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability
nvd
CVE-2022-30225P4HIGHCVSS 7.1v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-30225 [HIGH] CVE-2022-30225: Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
nvd
CVE-2019-1037P4HIGHCVSS 7.0v1803v19032019-07-15
CVE-2019-1037 [HIGH] CVE-2019-1037: An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles file
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1318P4MEDIUMCVSS 5.9v1803v19032019-10-10
CVE-2019-1318 [MEDIUM] CWE-290 CVE-2019-1318: A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Se
A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft Windows Transport Layer Security Spoofing Vulnerability'.
nvd
CVE-2019-1186P4HIGHCVSS 7.0v1803v1903+1 more2019-08-14
CVE-2019-1186 [HIGH] CVE-2019-1186: An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in mem
An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability b
nvd
CVE-2019-1173P4HIGHCVSS 7.0v1803v19032019-08-14
CVE-2019-1173 [HIGH] CVE-2019-1173: An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles obj
An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vuln
nvd
CVE-2019-1175P4HIGHCVSS 7.0v1803v19032019-08-14
CVE-2019-1175 [HIGH] CWE-269 CVE-2019-1175: An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in mem
An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnera
nvd
CVE-2019-1174P4HIGHCVSS 7.0v19032019-08-14
CVE-2019-1174 [HIGH] CWE-1257 CVE-2019-1174: An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles obj
An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses
nvd
CVE-2019-1177P4HIGHCVSS 7.0v1803v1903+1 more2019-08-14
CVE-2019-1177 [HIGH] CWE-269 CVE-2019-1177: An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memo
An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerab
nvd
CVE-2022-29135P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29135 [HIGH] CVE-2022-29135: Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
nvd
CVE-2022-29125P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29125 [HIGH] CVE-2022-29125: Windows Push Notifications Apps Elevation of Privilege Vulnerability
Windows Push Notifications Apps Elevation of Privilege Vulnerability
nvd
CVE-2022-21867P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21867 [HIGH] CVE-2022-21867: Windows Push Notifications Apps Elevation of Privilege Vulnerability
Windows Push Notifications Apps Elevation of Privilege Vulnerability
nvd
CVE-2023-28224P4HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28224 [HIGH] CWE-591 CVE-2023-28224: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2023-23407P4HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-23407 [HIGH] CWE-591 CVE-2023-23407: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd
CVE-2023-23414P4HIGHCVSS 7.1≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-23414 [HIGH] CWE-591 CVE-2023-23414: Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
nvd