cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 210 of 227
CVE-2018-0747P4MEDIUMCVSS 4.7v17092018-01-04
CVE-2018-0747 [MEDIUM] CVE-2018-0747: The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Win The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Information Disclosure Vulnerabili
nvd
CVE-2018-0830P4MEDIUMCVSS 4.7v17092018-02-15
CVE-2018-0830 [MEDIUM] CVE-2018-0830: The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Win The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka "Windows Information Disclosure Vulnerability"
nvd
CVE-2018-0829P4MEDIUMCVSS 4.7v17092018-02-15
CVE-2018-0829 [MEDIUM] CWE-200 CVE-2018-0829: The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Win The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka "Windows Information Disclosure Vulner
nvd
CVE-2021-28447P4MEDIUMCVSS 4.4v20h2v1909+2 more2021-04-13
CVE-2021-28447 [MEDIUM] CVE-2021-28447: Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability Windows Early Launch Antimalware Driver Security Feature Bypass Vulnerability
nvd
CVE-2019-1294P4MEDIUMCVSS 4.6v1803v19032019-09-11
CVE-2019-1294 [MEDIUM] CVE-2019-1294: A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging f A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2020-1578P4MEDIUMCVSS 4.7v1903v1909+1 more2020-08-17
CVE-2020-1578 [MEDIUM] CVE-2020-1578: An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass. An attacker who successfully exploited the vulnerability could retrieve the memory address of a kernel object. To exploit the vulnerability, an attacker would ha
nvd
CVE-2026-20928P4MEDIUMCVSS 4.6fixed in 10.0.14393.9060≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-20928 [MEDIUM] CWE-212 CVE-2026-20928: Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2024-38027P4MEDIUMCVSS 6.5fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38027 [MEDIUM] CWE-400 CVE-2024-38027: Windows Line Printer Daemon Service Denial of Service Vulnerability Windows Line Printer Daemon Service Denial of Service Vulnerability
nvd
CVE-2023-35331P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.60852023-07-11
CVE-2023-35331 [MEDIUM] CVE-2023-35331: Windows Local Security Authority (LSA) Denial of Service Vulnerability Windows Local Security Authority (LSA) Denial of Service Vulnerability
nvd
CVE-2023-36717P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36717 [MEDIUM] CVE-2023-36717: Windows Virtual Trusted Platform Module Denial of Service Vulnerability Windows Virtual Trusted Platform Module Denial of Service Vulnerability
nvd
CVE-2021-42274P4MEDIUMCVSS 6.5v20h2v2004+1 more2021-11-10
CVE-2021-42274 [MEDIUM] CVE-2021-42274: Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability Windows Hyper-V Discrete Device Assignment (DDA) Denial of Service Vulnerability
nvd
CVE-2021-26886P4MEDIUMCVSS 6.1v20h2v1909+2 more2021-03-11
CVE-2021-26886 [MEDIUM] CVE-2021-26886: User Profile Service Denial of Service Vulnerability User Profile Service Denial of Service Vulnerability
nvd
CVE-2021-28326P4MEDIUMCVSS 6.1v20h2v1909+2 more2021-04-13
CVE-2021-28326 [MEDIUM] CVE-2021-28326: Windows AppX Deployment Server Denial of Service Vulnerability Windows AppX Deployment Server Denial of Service Vulnerability
nvd
CVE-2020-0885P4MEDIUMCVSS 4.3v1803v1903+1 more2020-03-12
CVE-2020-0885 [MEDIUM] CVE-2020-0885: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2018-8116P4MEDIUMCVSS 5.5v(Server Core installation)2018-04-12
CVE-2018-8116 [MEDIUM] CVE-2018-8116: A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Mic A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Component Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2020-17045P4MEDIUMCVSS 5.5v20h2v1903+3 more2020-11-11
CVE-2020-17045 [MEDIUM] CVE-2020-17045: Windows KernelStream Information Disclosure Vulnerability Windows KernelStream Information Disclosure Vulnerability
nvd
CVE-2021-36962P4MEDIUMCVSS 5.5v20h2v2004+1 more2021-09-15
CVE-2021-36962 [MEDIUM] CVE-2021-36962: Windows Installer Information Disclosure Vulnerability Windows Installer Information Disclosure Vulnerability
nvd
CVE-2020-1261P4MEDIUMCVSS 5.5v1803v1903+2 more2020-06-09
CVE-2020-1261 [MEDIUM] CVE-2020-1261: An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles obje An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1263.
nvd
CVE-2020-1263P4MEDIUMCVSS 5.5v1803v1903+2 more2020-06-09
CVE-2020-1263 [MEDIUM] CVE-2020-1263: An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles obje An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error Reporting Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1261.
nvd
CVE-2022-29140P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29140 [MEDIUM] CVE-2022-29140: Windows Print Spooler Information Disclosure Vulnerability Windows Print Spooler Information Disclosure Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase