Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 212 of 227
CVE-2022-38026P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-38026 [MEDIUM] CVE-2022-38026: Windows DHCP Client Information Disclosure Vulnerability
Windows DHCP Client Information Disclosure Vulnerability
nvd
CVE-2023-28253P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28253 [MEDIUM] CVE-2023-28253: Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2022-41074P4MEDIUMCVSS 5.5≥ 10.0.14393.0, < 10.0.14393.55822022-12-13
CVE-2022-41074 [MEDIUM] CVE-2022-41074: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2018-8207P4MEDIUMCVSS 4.7v1709v18032018-06-14
CVE-2018-8207 [MEDIUM] CVE-2018-8207: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Server
nvd
CVE-2018-0843P4MEDIUMCVSS 4.7v17092018-02-15
CVE-2018-0843 [MEDIUM] CVE-2018-0843: The Windows kernel in Windows 10 version 1709 and Windows Server, version 1709 allows an information
The Windows kernel in Windows 10 version 1709 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0742, CVE-2018-0756, CVE-2018-0809 and CVE-2018-0820.
nvd
CVE-2019-0601P4MEDIUMCVSS 4.7v1709v18032019-03-05
CVE-2019-0601 [MEDIUM] CVE-2019-0601: An information disclosure vulnerability exists when the Human Interface Devices (HID) component impr
An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0600.
nvd
CVE-2019-1368P4MEDIUMCVSS 4.6v1803v19032019-10-10
CVE-2019-1368 [MEDIUM] CVE-2019-1368: A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging f
A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2024-38143P4MEDIUMCVSS 4.2fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38143 [MEDIUM] CWE-306 CVE-2024-38143: Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21900P4MEDIUMCVSS 4.6≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21900 [MEDIUM] CVE-2022-21900: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2026-20828P4MEDIUMCVSS 4.6fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20828 [MEDIUM] CWE-125 CVE-2026-20828: Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to d
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2025-59294P4MEDIUMCVSS 4.6fixed in 10.0.14393.8519≥ 10.0.14393.0, < 10.0.14393.85192025-10-14
CVE-2025-59294 [MEDIUM] CWE-200 CVE-2025-59294: Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unautho
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-50453P4MEDIUMCVSS 4.6fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50453 [MEDIUM] CWE-125 CVE-2026-50453: Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-49794P4MEDIUMCVSS 4.6fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-49794 [MEDIUM] CWE-125 CVE-2026-49794: Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2022-29121P4MEDIUMCVSS 6.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29121 [MEDIUM] CVE-2022-29121: Windows WLAN AutoConfig Service Denial of Service Vulnerability
Windows WLAN AutoConfig Service Denial of Service Vulnerability
nvd
CVE-2020-0616P4MEDIUMCVSS 5.5v1903v19092020-01-14
CVE-2020-0616 [MEDIUM] CWE-59 CVE-2020-0616: A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
nvd
CVE-2019-0754P4MEDIUMCVSS 5.5v1709v18032019-04-09
CVE-2019-0754 [MEDIUM] CVE-2019-0754: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2018-8612P4MEDIUMCVSS 5.5v1709v1803+1 more2018-12-12
CVE-2018-8612 [MEDIUM] CWE-20 CVE-2018-8612: A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values, aka "Connected User Experiences and Telemetry Service Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.
nvd
CVE-2019-1391P4MEDIUMCVSS 5.5v1803v19032019-11-12
CVE-2019-1391 [MEDIUM] CVE-2019-1391: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2018-12207.
nvd
CVE-2020-17071P4MEDIUMCVSS 5.5v20h2v1903+2 more2020-11-11
CVE-2020-17071 [MEDIUM] CVE-2020-17071: Windows Delivery Optimization Information Disclosure Vulnerability
Windows Delivery Optimization Information Disclosure Vulnerability
nvd
CVE-2025-21278P4MEDIUMCVSS 5.5fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21278 [MEDIUM] CWE-362 CVE-2025-21278: Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
nvd