Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 42 of 227
CVE-2024-21368P3HIGHCVSS 8.8fixed in 10.0.14393.6709≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21368 [HIGH] CWE-122 CVE-2024-21368: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21359P3HIGHCVSS 8.8fixed in 10.0.14393.6709≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21359 [HIGH] CWE-122 CVE-2024-21359: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21391P3HIGHCVSS 8.8fixed in 10.0.14393.6709≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21391 [HIGH] CWE-197 CVE-2024-21391: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21352P3HIGHCVSS 8.8fixed in 10.0.14393.6709≥ 10.0.14393.0, < 10.0.14393.67092024-02-13
CVE-2024-21352 [HIGH] CWE-197 CVE-2024-21352: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2026-20872P3MEDIUMCVSS 6.5fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20872 [MEDIUM] CWE-73 CVE-2026-20872: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-43517P3HIGHCVSS 8.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43517 [HIGH] CWE-122 CVE-2024-43517: Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
Microsoft ActiveX Data Objects Remote Code Execution Vulnerability
nvd
CVE-2024-38131P3HIGHCVSS 8.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38131 [HIGH] CWE-591 CVE-2024-38131: Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
nvd
CVE-2024-38053P3HIGHCVSS 8.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38053 [HIGH] CWE-416 CVE-2024-38053: Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
nvd
CVE-2024-43518P3HIGHCVSS 8.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43518 [HIGH] CWE-122 CVE-2024-43518: Windows Telephony Server Remote Code Execution Vulnerability
Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-49688P3HIGHCVSS 8.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49688 [HIGH] CWE-415 CVE-2025-49688: Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to e
Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-33679P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.53562022-09-13
CVE-2022-33679 [HIGH] CVE-2022-33679: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2018-0878P4LOWCVSS 3.1PoCv17092018-03-14
CVE-2018-0878 [LOW] CWE-611 CVE-2018-0878: Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how XML External Entities (XXE) are processed, aka "Windows Re
nvd
CVE-2024-38049P3HIGHCVSS 8.1fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38049 [HIGH] CWE-73 CVE-2024-38049: Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
nvd
CVE-2026-42989P3HIGHCVSS 7.8fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-42989 [HIGH] CWE-59 CVE-2026-42989: Improper link resolution before file access ('link following') in Winlogon allows an authorized atta
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
nvd
CVE-2021-1694P3CRITICALCVSS 9.8v20h2v1909+2 more2021-01-12
CVE-2021-1694 [CRITICAL] CWE-269 CVE-2021-1694: Windows Update Stack Elevation of Privilege Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2024-49124P3HIGHCVSS 8.1fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49124 [HIGH] CWE-362 CVE-2024-49124: Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
nvd
CVE-2025-62472P3HIGHCVSS 7.8fixed in 10.0.14393.8688≥ 10.0.14393.0, < 10.0.14393.86882025-12-09
CVE-2025-62472 [HIGH] CWE-416 CVE-2025-62472: Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attac
Use of uninitialized resource in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24064P3HIGHCVSS 8.1fixed in 10.0.14393.7876≥ 10.0.14393.0, < 10.0.14393.78762025-03-11
CVE-2025-24064 [HIGH] CWE-416 CVE-2025-24064: Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-49127P3HIGHCVSS 8.1fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49127 [HIGH] CWE-416 CVE-2024-49127: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2020-1374P3HIGHCVSS 7.5v1903v1909+1 more2020-07-14
CVE-2020-1374 [HIGH] CVE-2020-1374: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd