Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 201 of 227
CVE-2020-0941P4MEDIUMCVSS 5.5v1903v1909+2 more2020-09-11
CVE-2020-0941 [MEDIUM] CVE-2020-0941: <p>An information disclosure vulnerability exists when the win32k component improperly provides kern
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, an attacker would have to either log on locally to an affected system, or convince a locally au
nvd
CVE-2020-1083P4MEDIUMCVSS 5.5v1903v1909+2 more2020-09-11
CVE-2020-1083 [MEDIUM] CVE-2020-1083: <p>An information disclosure vulnerability exists when the Microsoft Windows Graphics Component impr
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially c
nvd
CVE-2020-1119P4MEDIUMCVSS 5.5v1903v1909+1 more2020-09-11
CVE-2020-1119 [MEDIUM] CVE-2020-1119: <p>An information disclosure vulnerability exists when StartTileData.dll improperly handles objects
An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
The
nvd
CVE-2020-0914P4MEDIUMCVSS 5.5v1903v1909+2 more2020-09-11
CVE-2020-0914 [MEDIUM] CVE-2020-0914: <p>An information disclosure vulnerability exists when the Windows State Repository Service improper
An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
nvd
CVE-2020-1250P4MEDIUMCVSS 5.5v1903v1909+2 more2020-09-11
CVE-2020-1250 [MEDIUM] CVE-2020-1250: <p>An information disclosure vulnerability exists when the win32k component improperly provides kern
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application
nvd
CVE-2021-26892P4MEDIUMCVSS 5.5v20h2v1909+2 more2021-03-11
CVE-2021-26892 [MEDIUM] CVE-2021-26892: Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
Windows Extensible Firmware Interface Security Feature Bypass Vulnerability
nvd
CVE-2019-0942P4MEDIUMCVSS 5.5v18032019-05-16
CVE-2019-0942 [MEDIUM] CVE-2019-0942: An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows
An elevation of privilege vulnerability exists in the Unified Write Filter (UWF) feature for Windows 10 when it improperly restricts access to the registry, aka 'Unified Write Filter Elevation of Privilege Vulnerability'.
nvd
CVE-2025-21321P4MEDIUMCVSS 5.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21321 [MEDIUM] CWE-532 CVE-2025-21321: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2025-21320P4MEDIUMCVSS 5.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21320 [MEDIUM] CWE-532 CVE-2025-21320: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2025-21318P4MEDIUMCVSS 5.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21318 [MEDIUM] CWE-532 CVE-2025-21318: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2025-21319P4MEDIUMCVSS 5.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21319 [MEDIUM] CWE-532 CVE-2025-21319: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2025-21316P4MEDIUMCVSS 5.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21316 [MEDIUM] CWE-532 CVE-2025-21316: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2021-31970P4MEDIUMCVSS 5.5v20h2v2004+1 more2021-06-08
CVE-2021-31970 [MEDIUM] CWE-639 CVE-2021-31970: Windows TCP/IP Driver Security Feature Bypass Vulnerability
Windows TCP/IP Driver Security Feature Bypass Vulnerability
nvd
CVE-2025-21323P4MEDIUMCVSS 5.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21323 [MEDIUM] CWE-532 CVE-2025-21323: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2025-27742P4MEDIUMCVSS 5.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27742 [MEDIUM] CWE-125 CVE-2025-27742: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-26207P4MEDIUMCVSS 5.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-04-09
CVE-2024-26207 [MEDIUM] CWE-125 CVE-2024-26207: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-28902P4MEDIUMCVSS 5.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-04-09
CVE-2024-28902 [MEDIUM] CWE-126 CVE-2024-28902: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-30039P4MEDIUMCVSS 5.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30039 [MEDIUM] CWE-126 CVE-2024-30039: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-38203P4MEDIUMCVSS 5.5fixed in 10.0.14393.7515≥ 10.0.14393.0, < 10.0.14393.75152024-11-12
CVE-2024-38203 [MEDIUM] CWE-693 CVE-2024-38203: Windows Package Library Manager Information Disclosure Vulnerability
Windows Package Library Manager Information Disclosure Vulnerability
nvd
CVE-2024-28900P4MEDIUMCVSS 5.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-04-09
CVE-2024-28900 [MEDIUM] CWE-126 CVE-2024-28900: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd