Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 192 of 227
CVE-2020-16921P4MEDIUMCVSS 5.5v1903v1909+1 more2020-10-16
CVE-2020-16921 [MEDIUM] CVE-2020-16921: <p>An information disclosure vulnerability exists in Text Services Framework when it fails to proper
An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights dir
nvd
CVE-2020-16897P4MEDIUMCVSS 5.5v1903v1909+2 more2020-10-16
CVE-2020-16897 [MEDIUM] CVE-2020-16897: <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) imp
An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have run a specially crafted application. The vulnerabi
nvd
CVE-2020-16854P4MEDIUMCVSS 5.5v1903v1909+2 more2020-09-11
CVE-2020-16854 [MEDIUM] CVE-2020-16854: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
nvd
CVE-2020-1548P4MEDIUMCVSS 5.5v1903v1909+1 more2020-08-17
CVE-2020-1548 [MEDIUM] CVE-2020-1548: An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles
An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to improperly disclose memory.
The security update addresses the vulnerability by correcting
nvd
CVE-2018-0854P4MEDIUMCVSS 5.3v1709v(Server Core installation)2018-05-09
CVE-2018-0854 [MEDIUM] CVE-2018-0854: A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attack
A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-0958, CVE-2018-8129, CVE-2018-8132.
nvd
CVE-2024-21313P4MEDIUMCVSS 5.3fixed in 10.0.14393.6614≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-21313 [MEDIUM] CWE-209 CVE-2024-21313: Windows TCP/IP Information Disclosure Vulnerability
Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2025-49722P4MEDIUMCVSS 5.7fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49722 [MEDIUM] CWE-400 CVE-2025-49722: Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.
nvd
CVE-2018-8204P4MEDIUMCVSS 5.3v1709v18032018-08-15
CVE-2018-8204 [MEDIUM] CVE-2018-8204: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8200.
nvd
CVE-2018-8200P4MEDIUMCVSS 5.3v1709v1803+1 more2018-08-15
CVE-2018-8200 [MEDIUM] CVE-2018-8200: A security feature bypass vulnerability exists in Device Guard that could allow an attacker to injec
A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8204.
nvd
CVE-2020-0989P4MEDIUMCVSS 5.5v1903v1909+1 more2020-09-11
CVE-2020-0989 [MEDIUM] CWE-862 CVE-2020-0989: <p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagno
An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a
nvd
CVE-2020-0805P4MEDIUMCVSS 5.5v20042020-09-11
CVE-2020-0805 [MEDIUM] CVE-2020-0805: <p>A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly han
A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a spe
nvd
CVE-2023-21729P4MEDIUMCVSS 5.3≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-21729 [MEDIUM] CWE-125 CVE-2023-21729: Remote Procedure Call Runtime Information Disclosure Vulnerability
Remote Procedure Call Runtime Information Disclosure Vulnerability
nvd
CVE-2025-27736P4MEDIUMCVSS 5.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27736 [MEDIUM] CWE-200 CVE-2025-27736: Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator a
Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally.
nvd
CVE-2025-53803P4MEDIUMCVSS 5.5fixed in 10.0.14393.8422≥ 10.0.14393.0, < 10.0.14393.84222025-09-09
CVE-2025-53803 [MEDIUM] CWE-209 CVE-2025-53803: Generation of error message containing sensitive information in Windows Kernel allows an authorized
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2025-32720P4MEDIUMCVSS 5.5fixed in 10.0.14393.8148≥ 10.0.14393.0, < 10.0.14393.81482025-06-10
CVE-2025-32720 [MEDIUM] CWE-125 CVE-2025-32720: Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
nvd
CVE-2025-49664P4MEDIUMCVSS 5.5fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49664 [MEDIUM] CWE-200 CVE-2025-49664: Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Hos
Exposure of sensitive information to an unauthorized actor in Windows User-Mode Driver Framework Host allows an authorized attacker to disclose information locally.
nvd
CVE-2025-48808P4MEDIUMCVSS 5.5fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-48808 [MEDIUM] CWE-200 CVE-2025-48808: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50431P4MEDIUMCVSS 5.5fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50431 [MEDIUM] CWE-200 CVE-2026-50431: Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
nvd
CVE-2023-28251P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.59212023-05-09
CVE-2023-28251 [MEDIUM] CVE-2023-28251: Windows Driver Revocation List Security Feature Bypass Vulnerability
Windows Driver Revocation List Security Feature Bypass Vulnerability
nvd
CVE-2025-59209P4MEDIUMCVSS 5.5≤ 10.0.14393.8519≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-59209 [MEDIUM] CWE-200 CVE-2025-59209: Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows
Exposure of sensitive information to an unauthorized actor in Windows Push Notification Core allows an authorized attacker to disclose information locally.
nvd