Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 64 of 227
CVE-2022-35756P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.52912023-05-31
CVE-2022-35756 [HIGH] CVE-2022-35756: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2018-8239P3MEDIUMCVSS 5.5v1709v(Server Core installation)2018-06-14
CVE-2018-8239 [MEDIUM] CWE-200 CVE-2018-8239: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2024-30025P3HIGHCVSS 7.8fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30025 [HIGH] CWE-125 CVE-2024-30025: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-0879P3HIGHCVSS 7.8v1709v18032019-04-09
CVE-2019-0879 [HIGH] CVE-2019-0879: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0877.
nvd
CVE-2018-0959P3HIGHCVSS 7.6v1709v1803+1 more2018-05-09
CVE-2018-0959 [HIGH] CWE-20 CVE-2018-0959: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2023-28244P3HIGHCVSS 8.1≥ 10.0.14393.0, < 10.0.14393.58502023-04-11
CVE-2023-28244 [HIGH] CWE-327 CVE-2023-28244: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-37966P3HIGHCVSS 8.1vN/A2022-11-09
CVE-2022-37966 [HIGH] CVE-2022-37966: Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
nvd
CVE-2024-38237P3HIGHCVSS 7.8fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38237 [HIGH] CWE-122 CVE-2024-38237: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-38242P3HIGHCVSS 7.8fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38242 [HIGH] CWE-122 CVE-2024-38242: Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-30068P3HIGHCVSS 8.8fixed in 10.0.14393.7070≥ 10.0.14393.0, < 10.0.14393.70702024-06-11
CVE-2024-30068 [HIGH] CWE-125 CVE-2024-30068: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-1471P3HIGHCVSS 8.2v1803v1903+1 more2019-12-10
CVE-2019-1471 [HIGH] CWE-20 CVE-2019-1471: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
nvd
CVE-2019-1484P3HIGHCVSS 7.8v1803v1903+1 more2019-12-10
CVE-2019-1484 [HIGH] CWE-20 CVE-2019-1484: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2025-49687P3HIGHCVSS 8.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49687 [HIGH] CWE-125 CVE-2025-49687: Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate p
Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-0738P3HIGHCVSS 8.8v1803v1903+1 more2020-02-11
CVE-2020-0738 [HIGH] CWE-787 CVE-2020-0738: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
nvd
CVE-2023-29351P3HIGHCVSS 8.1fixed in 10.0.14393.5989≥ 10.0.14393.0, < 10.0.14393.59892023-06-14
CVE-2023-29351 [HIGH] CWE-59 CVE-2023-29351: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-30150P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30150 [HIGH] CWE-287 CVE-2022-30150: Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
nvd
CVE-2020-1239P3HIGHCVSS 8.8v1803v1903+2 more2020-06-09
CVE-2020-1239 [HIGH] CVE-2020-1239: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238.
nvd
CVE-2021-33754P3HIGHCVSS 8.0v20h2v2004+1 more2021-07-14
CVE-2021-33754 [HIGH] CVE-2021-33754: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2020-0807P3HIGHCVSS 8.8v1803v1903+1 more2020-03-12
CVE-2020-0807 [HIGH] CVE-2020-0807: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0809, CVE-2020-0869.
nvd
CVE-2020-0809P3HIGHCVSS 8.8v1803v1903+1 more2020-03-12
CVE-2020-0809 [HIGH] CVE-2020-0809: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0869.
nvd