Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 37 of 227
CVE-2025-21286P3HIGHCVSS 8.8fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21286 [HIGH] CWE-122 CVE-2025-21286: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21266P3HIGHCVSS 8.8fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21266 [HIGH] CWE-122 CVE-2025-21266: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21273P3HIGHCVSS 8.8fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21273 [HIGH] CWE-122 CVE-2025-21273: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21282P3HIGHCVSS 8.8fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21282 [HIGH] CWE-122 CVE-2025-21282: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-27481P3HIGHCVSS 8.8fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27481 [HIGH] CWE-121 CVE-2025-27481: Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45602P3CRITICALCVSS 9.1fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45602 [CRITICAL] CWE-349 CVE-2026-45602: No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering ov
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
nvd
CVE-2022-30163P3HIGHCVSS 8.5v20h2≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30163 [HIGH] CWE-362 CVE-2022-30163: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2019-0796P4MEDIUMCVSS 5.5PoCv1709v18032019-04-09
CVE-2019-0796 [MEDIUM] CVE-2019-0796: An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV dr
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.
nvd
CVE-2026-32225P3HIGHCVSS 8.8fixed in 10.0.14393.9060≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-32225 [HIGH] CWE-693 CVE-2026-32225: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-54982P3HIGHCVSS 8.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-54982 [HIGH] CWE-191 CVE-2026-54982: Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an una
Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-26663P3HIGHCVSS 8.1fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-26663 [HIGH] CWE-416 CVE-2025-26663: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-17090P3CRITICALCVSS 9.8v20h2v1903+2 more2020-11-11
CVE-2020-17090 [CRITICAL] CVE-2020-17090: Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
Microsoft Defender for Endpoint Security Feature Bypass Vulnerability
nvd
CVE-2025-21294P3HIGHCVSS 8.1fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2020-17040P3CRITICALCVSS 9.8v20h2v1903+3 more2020-11-11
CVE-2020-17040 [CRITICAL] CVE-2020-17040: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2026-45635P3HIGHCVSS 8.1fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45635 [HIGH] CWE-843 CVE-2026-45635: Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll)
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45599P3HIGHCVSS 8.1fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-45599 [HIGH] CWE-416 CVE-2026-45599: Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21204P3HIGHCVSS 7.8fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-21204 [HIGH] CWE-59 CVE-2025-21204: Improper link resolution before file access ('link following') in Windows Update Stack allows an aut
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-43455P3CRITICALCVSS 9.8fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-43455 [CRITICAL] CWE-20 CVE-2024-43455: Windows Remote Desktop Licensing Service Spoofing Vulnerability
Windows Remote Desktop Licensing Service Spoofing Vulnerability
nvd
CVE-2020-1285P3HIGHCVSS 8.8v1903v1909+2 more2020-09-11
CVE-2020-1285 [HIGH] CVE-2020-1285: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users who
nvd
CVE-2020-1509P3HIGHCVSS 8.8v1903v1909+2 more2020-08-17
CVE-2020-1509 [HIGH] CVE-2020-1509: An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LS
An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service.
The security update addresses the vul
nvd