Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 187 of 227
CVE-2023-21693P4MEDIUMCVSS 5.7≥ 10.0.14393.0, < 10.0.14393.57172023-02-14
CVE-2023-21693 [MEDIUM] CWE-125 CVE-2023-21693: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2024-20692P4MEDIUMCVSS 5.7fixed in 10.0.14393.6614≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-20692 [MEDIUM] CWE-326 CVE-2024-20692: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2019-1227P4MEDIUMCVSS 5.5v1803v19032019-08-14
CVE-2019-1227 [MEDIUM] CWE-200 CVE-2019-1227: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted applic
nvd
CVE-2024-43547P4MEDIUMCVSS 5.9fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43547 [MEDIUM] CWE-325 CVE-2024-43547: Windows Kerberos Information Disclosure Vulnerability
Windows Kerberos Information Disclosure Vulnerability
nvd
CVE-2019-1171P4MEDIUMCVSS 5.6v1803v19032019-08-14
CVE-2019-1171 [MEDIUM] CWE-200 CVE-2019-1171: An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An atta
An information disclosure vulnerability exists in SymCrypt during the OAEP decryption stage. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulne
nvd
CVE-2018-8212P4MEDIUMCVSS 5.3v1709v18032018-06-14
CVE-2018-8212 [MEDIUM] CVE-2018-8212: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-20
nvd
CVE-2018-8492P4MEDIUMCVSS 5.3v1709v1803+1 more2018-10-10
CVE-2018-8492 [MEDIUM] CVE-2018-8492: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2025-21269P4MEDIUMCVSS 4.3fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21269 [MEDIUM] CWE-41 CVE-2025-21269: Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2023-36012P4MEDIUMCVSS 5.3≥ 10.0.14393.0, < 10.0.14393.65292023-12-12
CVE-2023-36012 [MEDIUM] CWE-908 CVE-2023-36012: DHCP Server Service Information Disclosure Vulnerability
DHCP Server Service Information Disclosure Vulnerability
nvd
CVE-2018-8222P4MEDIUMCVSS 5.3v1709v1803+1 more2018-07-11
CVE-2018-8222 [MEDIUM] CVE-2018-8222: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8221P4MEDIUMCVSS 5.3v1709v18032018-06-14
CVE-2018-8221 [MEDIUM] CVE-2018-8221: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-20
nvd
CVE-2018-8215P4MEDIUMCVSS 5.3v1709v18032018-06-14
CVE-2018-8215 [MEDIUM] CVE-2018-8215: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8201, CVE-2018-8211, CVE-20
nvd
CVE-2018-8211P4MEDIUMCVSS 5.3v1709v18032018-06-14
CVE-2018-8211 [MEDIUM] CVE-2018-8211: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8201, CVE-2018-8212, CVE-2018-8215, CVE-2018-821
nvd
CVE-2021-1645P4MEDIUMCVSS 5.5v20h2v1909+2 more2021-01-12
CVE-2021-1645 [MEDIUM] CVE-2021-1645: Windows Docker Information Disclosure Vulnerability
Windows Docker Information Disclosure Vulnerability
nvd
CVE-2021-1638P4MEDIUMCVSS 5.5v20h2v1909+1 more2021-01-12
CVE-2021-1638 [MEDIUM] CVE-2021-1638: Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For
Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG.
To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2019-1382P4MEDIUMCVSS 5.5v1803v19032019-11-12
CVE-2019-1382 [MEDIUM] CVE-2019-1382: An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to fi
An elevation of privilege vulnerability exists when ActiveX Installer service may allow access to files without proper authentication, aka 'Microsoft ActiveX Installer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1383P4MEDIUMCVSS 5.5v1903v1909+2 more2020-08-17
CVE-2020-1383 [MEDIUM] CVE-2020-1383: An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access en
An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system
To exploit this vulnerability, an attacker would need to run a specially crafted application against an RPC server which has Routin
nvd
CVE-2025-53136P4MEDIUMCVSS 5.5fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53136 [MEDIUM] CWE-200 CVE-2025-53136: Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authori
Exposure of sensitive information to an unauthorized actor in Windows NT OS Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2021-1731P4MEDIUMCVSS 5.5v20h2v1909+1 more2021-02-25
CVE-2021-1731 [MEDIUM] CWE-522 CVE-2021-1731: PFX Encryption Security Feature Bypass Vulnerability
PFX Encryption Security Feature Bypass Vulnerability
nvd
CVE-2020-16922P4MEDIUMCVSS 5.5v1903v1909+2 more2020-10-16
CVE-2020-16922 [MEDIUM] CWE-347 CVE-2020-16922: <p>A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker w
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update addr
nvd