Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 185 of 227
CVE-2026-45655P4MEDIUMCVSS 5.3fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45655 [MEDIUM] CWE-693 CVE-2026-45655: Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a securi
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2020-0746P4MEDIUMCVSS 5.5v1803v1903+1 more2020-02-11
CVE-2020-0746 [MEDIUM] CVE-2020-0746: An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle
An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Information Disclosure Vulnerability'.
nvd
CVE-2019-1096P4MEDIUMCVSS 5.5v1803v19032019-07-15
CVE-2019-1096 [MEDIUM] CWE-200 CVE-2019-1096: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
nvd
CVE-2026-24297P4MEDIUMCVSS 4.8fixed in 10.0.14393.8957≥ 10.0.14393.0, < 10.0.14393.89572026-03-10
CVE-2026-24297 [MEDIUM] CWE-362 CVE-2026-24297: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-35377P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.61672023-08-08
CVE-2023-35377 [MEDIUM] CWE-20 CVE-2023-35377: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-35376P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.61672023-08-08
CVE-2023-35376 [MEDIUM] CWE-20 CVE-2023-35376: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-28266P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28266 [MEDIUM] CWE-126 CVE-2023-28266: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2023-36909P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.61672023-08-08
CVE-2023-36909 [MEDIUM] CWE-191 CVE-2023-36909: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2020-1333P4MEDIUMCVSS 6.7v1903v1909+1 more2020-07-14
CVE-2020-1333 [MEDIUM] CVE-2020-1333: An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improper
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1258P4MEDIUMCVSS 6.7v1803v1903+2 more2020-06-09
CVE-2020-1258 [MEDIUM] CVE-2020-1258: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, ak
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1310P4MEDIUMCVSS 6.7v1803v1903+1 more2020-06-09
CVE-2020-1310 [MEDIUM] CVE-2020-1310: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1253.
nvd
CVE-2020-1253P4MEDIUMCVSS 6.7v1803v1903+2 more2020-06-09
CVE-2020-1253 [MEDIUM] CVE-2020-1253: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1310.
nvd
CVE-2021-43224P4MEDIUMCVSS 5.5v2004≥ 10.0.0, < 10.0.14393.48252021-12-15
CVE-2021-43224 [MEDIUM] CVE-2021-43224: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2020-1251P4MEDIUMCVSS 6.7v1803v1903+2 more2020-06-09
CVE-2020-1251 [MEDIUM] CVE-2020-1251: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1253, CVE-2020-1310.
nvd
CVE-2020-0904P4MEDIUMCVSS 6.5v1903v1909+2 more2020-09-11
CVE-2020-0904 [MEDIUM] CWE-20 CVE-2020-0904: <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properl
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.
To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.
nvd
CVE-2020-0728P4MEDIUMCVSS 5.5v1803v1903+1 more2020-02-11
CVE-2020-0728 [MEDIUM] CVE-2020-0728: An information vulnerability exists when Windows Modules Installer Service improperly discloses file
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
nvd
CVE-2025-21226P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21226 [MEDIUM] CWE-125 CVE-2025-21226: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21260P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21260 [MEDIUM] CWE-125 CVE-2025-21260: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21256P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21256 [MEDIUM] CWE-122 CVE-2025-21256: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21249P4MEDIUMCVSS 6.6fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21249 [MEDIUM] CWE-125 CVE-2025-21249: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd