cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 23 of 227
CVE-2019-0794P3HIGHCVSS 8.8v1709v18032019-04-09
CVE-2019-0794 [HIGH] CVE-2019-0794: A remote code execution vulnerability exists when OLE automation improperly handles objects in memor A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automation Remote Code Execution Vulnerability'.
nvd
CVE-2018-0743P3HIGHCVSS 7.0PoCv17092018-01-04
CVE-2018-0743 [HIGH] CVE-2018-0743: Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability".
nvd
CVE-2019-1212P3CRITICALCVSS 9.8v1803v1903+1 more2019-08-14
CVE-2019-1212 [CRITICAL] CWE-787 CVE-2019-1212: A memory corruption vulnerability exists in the Windows Server DHCP service when processing speciall A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding. To exploit the vulnerability, a remote unauthenticated attacker could send a specially crafted packet to an affected DH
nvd
CVE-2026-42990P2CRITICALCVSS 9.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-42990 [CRITICAL] CWE-122 CVE-2026-42990: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50694P2CRITICALCVSS 9.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50694 [CRITICAL] CWE-416 CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2018-0823P3HIGHCVSS 7.0PoCv17092018-02-15
CVE-2018-0823 [HIGH] CVE-2018-0823: The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an ele The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Named Pipe File System handles objects, aka "Named Pipe File System Elevation of Privilege Vulnerability".
nvd
CVE-2019-0845P3HIGHCVSS 8.8v1709v18032019-04-09
CVE-2019-0845 [HIGH] CVE-2019-0845: A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCvt Interface Remote Code Execution Vulnerability'.
nvd
CVE-2020-1281P3HIGHCVSS 8.8v1803v1903+2 more2020-06-09
CVE-2020-1281 [HIGH] CWE-190 CVE-2020-1281: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2024-30010P2HIGHCVSS 8.8fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30010 [HIGH] CWE-23 CVE-2024-30010: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2025-27480P3HIGHCVSS 8.1fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27480 [HIGH] CWE-416 CVE-2025-27480: Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code ove Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43593P2HIGHCVSS 8.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43593 [HIGH] CWE-20 CVE-2024-43593: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43592P2HIGHCVSS 8.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43592 [HIGH] CWE-20 CVE-2024-43592: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38260P2HIGHCVSS 8.8fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38260 [HIGH] CWE-908 CVE-2024-38260: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2020-0662P3HIGHCVSS 8.8v1803v1903+1 more2020-02-11
CVE-2020-0662 [HIGH] CVE-2020-0662: A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
nvd
CVE-2025-64678P2HIGHCVSS 8.8fixed in 10.0.14393.8594≥ 10.0.14393.0, < 10.0.14393.85942025-12-09
CVE-2025-64678 [HIGH] CWE-122 CVE-2025-64678: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-1365P3CRITICALCVSS 9.9v1803v19032019-10-10
CVE-2019-1365 [CRITICAL] CVE-2019-1365: An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length o An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the
nvd
CVE-2026-50369P2HIGHCVSS 8.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50369 [HIGH] CWE-362 CVE-2026-50369: Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privilege Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2018-8468P3MEDIUMCVSS 4.7PoCv1709v1803+1 more2018-09-13
CVE-2018-8468 [MEDIUM] CVE-2018-8468: An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0842P3HIGHCVSS 8.8v1709v18032019-04-09
CVE-2019-0842 [HIGH] CWE-787 CVE-2019-0842: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.
nvd
CVE-2022-21993P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.49462022-02-09
CVE-2022-21993 [HIGH] CVE-2022-21993: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase