Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 178 of 227
CVE-2018-0976P4MEDIUMCVSS 5.3v1709v(Server Core installation)2018-04-12
CVE-2018-0976 [MEDIUM] CVE-2018-0976: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.
nvd
CVE-2022-37977P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-37977 [MEDIUM] CVE-2022-37977: Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
nvd
CVE-2019-1416P4HIGHCVSS 7.0v1803v19032019-11-12
CVE-2019-1416 [HIGH] CWE-362 CVE-2019-1416: An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linu
An elevation of privilege vulnerability exists due to a race condition in Windows Subsystem for Linux, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'.
nvd
CVE-2023-35318P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35318 [MEDIUM] CWE-125 CVE-2023-35318: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-35319P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35319 [MEDIUM] CWE-125 CVE-2023-35319: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-35314P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35314 [MEDIUM] CWE-125 CVE-2023-35314: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33164P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-33164 [MEDIUM] CWE-125 CVE-2023-33164: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2025-50158P4HIGHCVSS 7.0fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-50158 [HIGH] CWE-367 CVE-2025-50158: Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to
Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2021-33764P4MEDIUMCVSS 5.9v20h2v2004+1 more2021-07-14
CVE-2021-33764 [MEDIUM] CVE-2021-33764: Windows Key Distribution Center Information Disclosure Vulnerability
Windows Key Distribution Center Information Disclosure Vulnerability
nvd
CVE-2023-21560P4MEDIUMCVSS 6.6≥ 10.0.14393.0, < 10.0.14393.56482023-01-10
CVE-2023-21560 [MEDIUM] CWE-122 CVE-2023-21560: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28269P4MEDIUMCVSS 6.8≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28269 [MEDIUM] CWE-122 CVE-2023-28269: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28249P4MEDIUMCVSS 6.8≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28249 [MEDIUM] CWE-863 CVE-2023-28249: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2019-1324P4MEDIUMCVSS 5.3v1803v19032019-11-12
CVE-2019-1324 [MEDIUM] CWE-200 CVE-2019-1324: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
nvd
CVE-2024-38013P4MEDIUMCVSS 6.7fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38013 [MEDIUM] CWE-59 CVE-2024-38013: Microsoft Windows Server Backup Elevation of Privilege Vulnerability
Microsoft Windows Server Backup Elevation of Privilege Vulnerability
nvd
CVE-2026-45608P4MEDIUMCVSS 6.8fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45608 [MEDIUM] CWE-125 CVE-2026-45608: Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information lo
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
nvd
CVE-2021-34493P4MEDIUMCVSS 6.7v20h2v2004+1 more2021-07-14
CVE-2021-34493 [MEDIUM] CWE-269 CVE-2021-34493: Windows Partition Management Driver Elevation of Privilege Vulnerability
Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-35754P4MEDIUMCVSS 6.7≥ 10.0.14393.0, < 10.0.14393.52912023-05-31
CVE-2022-35754 [MEDIUM] CVE-2022-35754: Unified Write Filter Elevation of Privilege Vulnerability
Unified Write Filter Elevation of Privilege Vulnerability
nvd
CVE-2022-22028P4MEDIUMCVSS 5.9v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22028 [MEDIUM] CVE-2022-22028: Windows Network File System Information Disclosure Vulnerability
Windows Network File System Information Disclosure Vulnerability
nvd
CVE-2021-41338P4MEDIUMCVSS 5.5v20h2v2004+1 more2021-10-13
CVE-2021-41338 [MEDIUM] CVE-2021-41338: Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
nvd
CVE-2024-21316P4MEDIUMCVSS 6.1≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-21316 [MEDIUM] CWE-20 CVE-2024-21316: Windows Server Key Distribution Service Security Feature Bypass
Windows Server Key Distribution Service Security Feature Bypass
nvd