cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 175 of 227
CVE-2022-29151P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29151 [HIGH] CVE-2022-29151: Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
nvd
CVE-2022-29150P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29150 [HIGH] CVE-2022-29150: Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
nvd
CVE-2023-35329P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35329 [MEDIUM] CWE-400 CVE-2023-35329: Windows Authentication Denial of Service Vulnerability Windows Authentication Denial of Service Vulnerability
nvd
CVE-2022-29138P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29138 [HIGH] CVE-2022-29138: Windows Clustered Shared Volume Elevation of Privilege Vulnerability Windows Clustered Shared Volume Elevation of Privilege Vulnerability
nvd
CVE-2022-29106P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29106 [HIGH] CVE-2022-29106: Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
nvd
CVE-2024-43534P4MEDIUMCVSS 6.5fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43534 [MEDIUM] CWE-125 CVE-2024-43534: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-38027P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-38027 [HIGH] CWE-362 CVE-2022-38027: Windows Storage Elevation of Privilege Vulnerability Windows Storage Elevation of Privilege Vulnerability
nvd
CVE-2023-29368P4HIGHCVSS 7.0fixed in 10.0.14393.5989≥ 10.0.14393.0, < 10.0.14393.59892023-06-14
CVE-2023-29368 [HIGH] CWE-415 CVE-2023-29368: Windows Filtering Platform Elevation of Privilege Vulnerability Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-28216P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28216 [HIGH] CVE-2023-28216: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2022-26828P4HIGHCVSS 7.0v20h22022-04-15
CVE-2022-26828 [HIGH] CWE-362 CVE-2022-26828: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-6769P4MEDIUMCVSS 6.7v10.0.02024-09-26
CVE-2024-6769 [MEDIUM] CWE-426 CVE-2024-6769: A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Micro A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.
nvd
CVE-2023-23385P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-23385 [HIGH] CWE-190 CVE-2023-23385: Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
nvd
CVE-2022-26807P4HIGHCVSS 7.0v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-26807 [HIGH] CWE-362 CVE-2022-26807: Windows Work Folder Service Elevation of Privilege Vulnerability Windows Work Folder Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21542P4HIGHCVSS 7.0≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21542 [HIGH] CWE-59 CVE-2023-21542: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2018-0890P4MEDIUMCVSS 5.3v1709v(Server Core installation)2018-04-12
CVE-2018-0890 [MEDIUM] CVE-2018-0890: A security feature bypass vulnerability exists when Active Directory incorrectly applies Network Iso A security feature bypass vulnerability exists when Active Directory incorrectly applies Network Isolation settings, aka "Active Directory Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2022-30205P4MEDIUMCVSS 6.6v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-30205 [MEDIUM] CWE-362 CVE-2022-30205: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2025-48800P4MEDIUMCVSS 6.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-48800 [MEDIUM] CWE-693 CVE-2025-48800: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48804P4MEDIUMCVSS 6.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-48804 [MEDIUM] CWE-349 CVE-2025-48804: Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorize Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2025-48818P4MEDIUMCVSS 6.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-48818 [MEDIUM] CWE-367 CVE-2025-48818: Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attack Time-of-check time-of-use (toctou) race condition in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2021-33744P4MEDIUMCVSS 6.7v20h2v20042021-07-14
CVE-2021-33744 [MEDIUM] CVE-2021-33744: Windows Secure Kernel Mode Security Feature Bypass Vulnerability Windows Secure Kernel Mode Security Feature Bypass Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase