cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 43 of 227
CVE-2025-29810P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-29810 [HIGH] CWE-284 CVE-2025-29810: Improper access control in Active Directory Domain Services allows an authorized attacker to elevate Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-53720P3HIGHCVSS 8.0fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-53720 [HIGH] CWE-122 CVE-2025-53720: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2025-50160P3HIGHCVSS 8.0fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-50160 [HIGH] CWE-122 CVE-2025-50160: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2025-50162P3HIGHCVSS 8.0fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-50162 [HIGH] CWE-122 CVE-2025-50162: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2025-50164P3HIGHCVSS 8.0fixed in 10.0.14393.8330≥ 10.0.14393.0, < 10.0.14393.83302025-08-12
CVE-2025-50164 [HIGH] CWE-122 CVE-2025-50164: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-20922P3HIGHCVSS 7.8fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20922 [HIGH] CWE-122 CVE-2026-20922: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2020-0922P3HIGHCVSS 8.8v1903v1909+2 more2020-09-11
CVE-2020-0922 [HIGH] CVE-2020-0922: <p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles ob A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript.
nvd
CVE-2026-50683P3HIGHCVSS 8.0fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50683 [HIGH] CWE-122 CVE-2026-50683: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privilege Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2018-8345P3HIGHCVSS 7.5v1709v18032018-08-15
CVE-2018-8345 [HIGH] CWE-94 CVE-2018-8345: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10,
nvd
CVE-2020-1561P3HIGHCVSS 8.8v1903v1909+2 more2020-08-17
CVE-2020-1561 [HIGH] CVE-2020-1561: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correct
nvd
CVE-2026-20848P3HIGHCVSS 7.5fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20848 [HIGH] CWE-362 CVE-2026-20848: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2020-1339P3HIGHCVSS 8.8v1903v1909+2 more2020-08-17
CVE-2020-1339 [HIGH] CVE-2020-1339: A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objec A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2026-50685P3HIGHCVSS 7.5fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50685 [HIGH] CWE-415 CVE-2026-50685: Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-58531P3HIGHCVSS 7.5fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-58531 [HIGH] CWE-362 CVE-2026-58531: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2021-42291P3HIGHCVSS 8.8v2004≥ 10.0.0, < 10.0.14393.47702021-11-10
CVE-2021-42291 [HIGH] CWE-269 CVE-2021-42291: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2021-42282P3HIGHCVSS 8.8v2004≥ 10.0.0, < 10.0.14393.47702021-11-10
CVE-2021-42282 [HIGH] CWE-269 CVE-2021-42282: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2020-1508P3HIGHCVSS 8.8v1903v1909+2 more2020-09-11
CVE-2020-1508 [HIGH] CVE-2020-1508: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2026-58608P3HIGHCVSS 7.5fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-58608 [HIGH] CWE-362 CVE-2026-58608: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
nvd
CVE-2022-21851P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21851 [HIGH] CVE-2022-21851: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-21850P3HIGHCVSS 8.8≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21850 [HIGH] CVE-2022-21850: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase