cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 45 of 227
CVE-2024-43519P3HIGHCVSS 8.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43519 [HIGH] CWE-197 CVE-2024-43519: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-29362P3HIGHCVSS 8.8fixed in 10.0.14393.5989≥ 10.0.14393.0, < 10.0.14393.59892023-06-14
CVE-2023-29362 [HIGH] CWE-122 CVE-2023-29362: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2026-20843P3HIGHCVSS 7.8fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20843 [HIGH] CWE-284 CVE-2026-20843: Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized att Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49740P3HIGHCVSS 8.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49740 [HIGH] CWE-693 CVE-2025-49740: Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a secu Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-21238P3HIGHCVSS 7.8fixed in 10.0.14393.8868≥ 10.0.14393.0, < 10.0.14393.88682026-02-10
CVE-2026-21238 [HIGH] CWE-284 CVE-2026-21238: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-26919P3HIGHCVSS 8.1v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-26919 [HIGH] CVE-2022-26919: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-50509P3HIGHCVSS 7.8fixed in 10.0.14393.9339≥ 10.0.14393.0, < 10.0.14393.93392026-07-14
CVE-2026-50509 [HIGH] CWE-502 CVE-2026-50509: Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-30141P3HIGHCVSS 8.1v20h2≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30141 [HIGH] CVE-2022-30141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2026-27914P3HIGHCVSS 7.8fixed in 10.0.14393.9060≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-27914 [HIGH] CWE-284 CVE-2026-27914: Improper access control in Microsoft Management Console allows an authorized attacker to elevate pri Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
nvd
CVE-2019-0538P3HIGHCVSS 7.8v1709v1803+1 more2019-01-08
CVE-2019-0538 [HIGH] CVE-2019-0538: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2025-24035P3HIGHCVSS 8.1fixed in 10.0.14393.7876≥ 10.0.14393.0, < 10.0.14393.78762025-03-11
CVE-2025-24035 [HIGH] CWE-591 CVE-2025-24035: Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unau Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21295P3HIGHCVSS 8.1fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21295 [HIGH] CWE-416 CVE-2025-21295: SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
nvd
CVE-2019-0889P3HIGHCVSS 7.8v1803v19032019-05-16
CVE-2019-0889 [HIGH] CVE-2019-0889: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2019-0899P3HIGHCVSS 7.8v1803v19032019-05-16
CVE-2019-0899 [HIGH] CVE-2019-0899: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0900, CVE
nvd
CVE-2019-0891P3HIGHCVSS 7.8v1803v19032019-05-16
CVE-2019-0891 [HIGH] CVE-2019-0891: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2024-49118P3HIGHCVSS 8.1fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49118 [HIGH] CWE-416 CVE-2024-49118: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2020-1408P3HIGHCVSS 8.8v1903v1909+1 more2020-07-14
CVE-2020-1408 [HIGH] CWE-346 CVE-2020-1408: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2025-21297P3HIGHCVSS 8.1fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21297 [HIGH] CWE-416 CVE-2025-21297: Windows Remote Desktop Services Remote Code Execution Vulnerability Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
CVE-2026-20925P3MEDIUMCVSS 6.5fixed in 10.0.14393.8783≥ 10.0.14393.0, < 10.0.14393.87832026-01-13
CVE-2026-20925 [MEDIUM] CWE-73 CVE-2026-20925: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-49108P3HIGHCVSS 8.1fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49108 [HIGH] CWE-416 CVE-2024-49108: Windows Remote Desktop Services Remote Code Execution Vulnerability Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase