cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 24 of 227
CVE-2023-21708P2CRITICALCVSS 9.8≥ 10.0.14393.0, < 10.0.14393.57862023-03-14
CVE-2023-21708 [CRITICAL] CWE-191 CVE-2023-21708: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-34494P3HIGHCVSS 8.8v20h2v2004+1 more2021-07-14
CVE-2021-34494 [HIGH] CVE-2021-34494: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2018-0822P3HIGHCVSS 7.0PoCv17092018-02-15
CVE-2018-0822 [HIGH] CVE-2018-0822: NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way NTFS handles objects, aka "Windows NTFS Global Reparse Point Elevation of Privilege Vulnerability".
nvd
CVE-2019-1384P3CRITICALCVSS 9.9v1803v19032019-11-12
CVE-2019-1384 [CRITICAL] CWE-522 CVE-2019-1384: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the sessio A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
nvd
CVE-2018-0821P3HIGHCVSS 7.0PoCv17092018-02-15
CVE-2018-0821 [HIGH] CWE-269 CVE-2018-0821: AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way constrained impersonations are handled, aka "Windows AppContainer Elevation Of Privilege Vulnerability".
nvd
CVE-2022-29129P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29129 [HIGH] CVE-2022-29129: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29128P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29128 [HIGH] CVE-2022-29128: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29141P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-29141 [HIGH] CVE-2022-29141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2018-8475P3HIGHCVSS 8.8v1709v1803+1 more2018-09-13
CVE-2018-8475 [HIGH] CVE-2018-8475: A remote code execution vulnerability exists when Windows does not properly handle specially crafted A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2020-1299P3HIGHCVSS 8.8v1803v1903+2 more2020-06-09
CVE-2020-1299 [HIGH] CVE-2020-1299: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2019-0765P3HIGHCVSS 8.8v1709v18032019-04-09
CVE-2019-0765 [HIGH] CWE-787 CVE-2019-0765: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.
nvd
CVE-2025-26647P2HIGHCVSS 8.8fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-26647 [HIGH] CWE-20 CVE-2025-26647: Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges ov Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2020-1435P3HIGHCVSS 8.8v1903v1909+1 more2020-07-14
CVE-2020-1435 [HIGH] CVE-2020-1435: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2020-1248P3HIGHCVSS 8.8v1903v1909+1 more2020-06-09
CVE-2020-1248 [HIGH] CVE-2020-1248: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2026-42985P3HIGHCVSS 8.8fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-42985 [HIGH] CWE-416 CVE-2026-42985: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-1060P3HIGHCVSS 8.8v1803v19032019-10-10
CVE-2019-1060 [HIGH] CWE-611 CVE-2019-1060: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2026-49178P3HIGHCVSS 8.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-49178 [HIGH] CWE-122 CVE-2026-49178: Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to exec Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
nvd
CVE-2019-0756P3HIGHCVSS 8.8v1709v18032019-04-09
CVE-2019-0756 [HIGH] CWE-611 CVE-2019-0756: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2019-1291P3HIGHCVSS 8.8v1803v19032019-09-11
CVE-2019-1291 [HIGH] CVE-2019-1291: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1290.
nvd
CVE-2019-1290P3HIGHCVSS 8.8v1803v19032019-09-11
CVE-2019-1290 [HIGH] CVE-2019-1290: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1291.
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase