Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 35 of 227
CVE-2021-28336P3HIGHCVSS 8.8v20h2v1909+2 more2021-04-13
CVE-2021-28336 [HIGH] CVE-2021-28336: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28353P3HIGHCVSS 8.8v20h2v1909+2 more2021-04-13
CVE-2021-28353 [HIGH] CVE-2021-28353: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-26881P3HIGHCVSS 8.8v20h2v1909+2 more2021-03-11
CVE-2021-26881 [HIGH] CVE-2021-26881: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2023-35381P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.61672023-08-08
CVE-2023-35381 [HIGH] CWE-190 CVE-2023-35381: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2023-21727P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-21727 [HIGH] CWE-122 CVE-2023-21727: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2024-38128P3HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38128 [HIGH] CWE-190 CVE-2024-38128: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38121P3HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38121 [HIGH] CWE-122 CVE-2024-38121: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38115P3HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38115 [HIGH] CWE-122 CVE-2024-38115: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-38130P3HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38130 [HIGH] CWE-122 CVE-2024-38130: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38120P3HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38120 [HIGH] CWE-122 CVE-2024-38120: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30013P3HIGHCVSS 8.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-30013 [HIGH] CWE-415 CVE-2024-30013: Windows MultiPoint Services Remote Code Execution Vulnerability
Windows MultiPoint Services Remote Code Execution Vulnerability
nvd
CVE-2024-38154P3HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38154 [HIGH] CWE-122 CVE-2024-38154: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38114P3HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38114 [HIGH] CWE-122 CVE-2024-38114: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-49086P3HIGHCVSS 8.8fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49086 [HIGH] CWE-122 CVE-2024-49086: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-49085P3HIGHCVSS 8.8fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49085 [HIGH] CWE-122 CVE-2024-49085: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-27477P3HIGHCVSS 8.8fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27477 [HIGH] CWE-122 CVE-2025-27477: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-1125P3MEDIUMCVSS 5.6PoCv1803v1903+1 more2019-09-03
CVE-2019-1125 [MEDIUM] CVE-2019-1125: An information disclosure vulnerability exists when certain central processing units (CPU) speculati
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The v
nvd
CVE-2024-43622P3HIGHCVSS 8.8fixed in 10.0.14393.7515≥ 10.0.14393.0, < 10.0.14393.75152024-11-12
CVE-2024-43622 [HIGH] CWE-122 CVE-2024-43622: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-43620P3HIGHCVSS 8.8fixed in 10.0.14393.7515≥ 10.0.14393.0, < 10.0.14393.75152024-11-12
CVE-2024-43620 [HIGH] CWE-122 CVE-2024-43620: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-43621P3HIGHCVSS 8.8fixed in 10.0.14393.7515≥ 10.0.14393.0, < 10.0.14393.75152024-11-12
CVE-2024-43621 [HIGH] CWE-122 CVE-2024-43621: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd