cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 179 of 227
CVE-2022-34709P4MEDIUMCVSS 6.0v20h2≥ 10.0.14393.0, < 10.0.14393.52912022-08-09
CVE-2022-34709 [MEDIUM] CWE-843 CVE-2022-34709: Windows Defender Credential Guard Security Feature Bypass Vulnerability Windows Defender Credential Guard Security Feature Bypass Vulnerability
nvd
CVE-2026-20818P4MEDIUMCVSS 6.2fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20818 [MEDIUM] CWE-532 CVE-2026-20818: Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker t Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-59258P4MEDIUMCVSS 6.2≤ 10.0.14393.8519≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-59258 [MEDIUM] CWE-532 CVE-2025-59258: Insertion of sensitive information into log file in Active Directory Federation Services allows an u Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
nvd
CVE-2019-1470P4MEDIUMCVSS 6.0v1803v1903+1 more2019-12-10
CVE-2019-1470 [MEDIUM] CWE-20 CVE-2019-1470: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2025-27735P4MEDIUMCVSS 6.0fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27735 [MEDIUM] CWE-345 CVE-2025-27735: Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclav Insufficient verification of data authenticity in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2020-16919P4MEDIUMCVSS 5.5v1903v1909+2 more2020-10-16
CVE-2020-16919 [MEDIUM] CVE-2020-16919: <p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files. An attacker with unprivileged access to a vulnerable system could exploit this vulnerability. The security update addresses the vul
nvd
CVE-2022-30154P4MEDIUMCVSS 5.3≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30154 [MEDIUM] CVE-2022-30154: Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability
nvd
CVE-2026-50475P4MEDIUMCVSS 5.5fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50475 [MEDIUM] CWE-126 CVE-2026-50475: Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20839P4MEDIUMCVSS 5.5fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20839 [MEDIUM] CWE-284 CVE-2026-20839: Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker t Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50341P4MEDIUMCVSS 5.5fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50341 [MEDIUM] CWE-126 CVE-2026-50341: Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42914P4MEDIUMCVSS 5.3fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-42914 [MEDIUM] CWE-125 CVE-2026-42914: Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
cvelistv5nvd
CVE-2019-1317P4HIGHCVSS 7.3v1803v19032019-10-10
CVE-2019-1317 [HIGH] CWE-59 CVE-2019-1317: A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
nvd
CVE-2020-0890P4MEDIUMCVSS 6.5v1903v1909+1 more2020-09-11
CVE-2020-0890 [MEDIUM] CVE-2020-0890: <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properl A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application. The sec
nvd
CVE-2024-30037P4MEDIUMCVSS 5.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30037 [MEDIUM] CWE-125 CVE-2024-30037: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-0716P4MEDIUMCVSS 5.8v1803v1903+1 more2019-08-14
CVE-2019-0716 [MEDIUM] CVE-2019-0716: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an
nvd
CVE-2021-33745P4MEDIUMCVSS 6.5v20h2v2004+1 more2021-07-14
CVE-2021-33745 [MEDIUM] CVE-2021-33745: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2021-34499P4MEDIUMCVSS 6.5v20h2v2004+1 more2021-07-14
CVE-2021-34499 [MEDIUM] CVE-2021-34499: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2019-0886P4MEDIUMCVSS 6.8v1803v19032019-05-16
CVE-2019-0886 [MEDIUM] CWE-20 CVE-2019-0886: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2021-40463P4MEDIUMCVSS 6.5v20h2v2004+1 more2021-10-13
CVE-2021-40463 [MEDIUM] CVE-2021-40463: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2020-0730P4HIGHCVSS 7.1v1803v1903+1 more2020-02-11
CVE-2020-0730 [HIGH] CWE-59 CVE-2020-0730: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase