cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 53 of 227
CVE-2019-0885P3HIGHCVSS 7.8v1709v18032019-05-16
CVE-2019-0885 [HIGH] CWE-20 CVE-2019-0885: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2025-59517P3HIGHCVSS 7.8fixed in 10.0.14393.8688≥ 10.0.14393.0, < 10.0.14393.86882025-12-09
CVE-2025-59517 [HIGH] CWE-284 CVE-2025-59517: Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privi Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24045P3HIGHCVSS 8.1fixed in 10.0.14393.7876≥ 10.0.14393.0, < 10.0.14393.78762025-03-11
CVE-2025-24045 [HIGH] CWE-591 CVE-2025-24045: Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unau Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-41773P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-41773 [HIGH] CWE-416 CVE-2023-41773: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41774P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-41774 [HIGH] CWE-416 CVE-2023-41774: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41767P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-41767 [HIGH] CWE-416 CVE-2023-41767: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-38166P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-38166 [HIGH] CWE-416 CVE-2023-38166: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41768P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-41768 [HIGH] CWE-416 CVE-2023-41768: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41771P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-41771 [HIGH] CWE-416 CVE-2023-41771: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41765P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-41765 [HIGH] CWE-416 CVE-2023-41765: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41769P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-41769 [HIGH] CWE-416 CVE-2023-41769: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41770P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-41770 [HIGH] CWE-416 CVE-2023-41770: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2026-42986P3HIGHCVSS 7.8fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-42986 [HIGH] CWE-416 CVE-2026-42986: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-28283P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.59212023-05-09
CVE-2023-28283 [HIGH] CWE-591 CVE-2023-28283: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22039P3HIGHCVSS 7.5v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-22039 [HIGH] CVE-2022-22039: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2019-1337P4MEDIUMCVSS 5.5PoCv19032019-10-10
CVE-2019-1337 [MEDIUM] CWE-200 CVE-2019-1337: An information disclosure vulnerability exists when Windows Update Client fails to properly handle o An information disclosure vulnerability exists when Windows Update Client fails to properly handle objects in memory, aka 'Windows Update Client Information Disclosure Vulnerability'.
nvd
CVE-2022-30139P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30139 [HIGH] CVE-2022-30139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2019-1359P3HIGHCVSS 7.8v1803v19032019-10-10
CVE-2019-1359 [HIGH] CVE-2019-1359: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1358.
nvd
CVE-2026-33826P3HIGHCVSS 8.0fixed in 10.0.14393.9060≥ 10.0.14393.0, < 10.0.14393.90602026-04-14
CVE-2026-33826 [HIGH] CWE-20 CVE-2026-33826: Improper input validation in Windows Active Directory allows an authorized attacker to execute code Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
nvd
CVE-2025-64679P3HIGHCVSS 7.8fixed in 10.0.14393.8519≥ 10.0.14393.0, < 10.0.14393.85192025-12-09
CVE-2025-64679 [HIGH] CWE-122 CVE-2025-64679: Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate priv Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase