Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 66 of 227
CVE-2019-0897P3HIGHCVSS 7.8v1803v19032019-05-16
CVE-2019-0897 [HIGH] CVE-2019-0897: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2019-0895P3HIGHCVSS 7.8v1803v19032019-05-16
CVE-2019-0895 [HIGH] CVE-2019-0895: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2019-0893P3HIGHCVSS 7.8v1803v19032019-05-16
CVE-2019-0893 [HIGH] CVE-2019-0893: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE-2019-0900, CVE
nvd
CVE-2020-0948P3HIGHCVSS 8.8v1803v1903+1 more2020-04-15
CVE-2020-0948 [HIGH] CWE-787 CVE-2020-0948: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0949, CVE-2020-0950.
nvd
CVE-2020-0949P3HIGHCVSS 8.8v1803v1903+1 more2020-04-15
CVE-2020-0949 [HIGH] CVE-2020-0949: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0948, CVE-2020-0950.
nvd
CVE-2020-0950P3HIGHCVSS 8.8v1803v1903+1 more2020-04-15
CVE-2020-0950 [HIGH] CVE-2020-0950: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0948, CVE-2020-0949.
nvd
CVE-2020-0708P3HIGHCVSS 7.8v1803v1903+1 more2020-02-11
CVE-2020-0708 [HIGH] CVE-2020-0708: A remote code execution vulnerability exists when the Windows Imaging Library improperly handles mem
A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.To exploit this vulnerability, an attacker would first have to coerce a victim to open a specially crafted file.The security update addresses the vulnerability by correcting how the Windows Imaging Library handles memory., aka 'Windows Imaging Library Remote
nvd
CVE-2019-1183P3HIGHCVSS 8.8v1803v19032019-08-14
CVE-2019-1183 [HIGH] CVE-2019-1183: This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by th
This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by the security updates for the vulnerability discussed in CVE-2019-1194. No update is required.
nvd
CVE-2018-0746P4MEDIUMCVSS 4.7PoCv17092018-01-04
CVE-2018-0746 [MEDIUM] CVE-2018-0746: The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 160
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0745 and C
nvd
CVE-2022-38051P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-38051 [HIGH] CVE-2022-38051: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-21307P3HIGHCVSS 7.5fixed in 10.0.14393.6614≥ 10.0.14393.0, < 10.0.14393.66142024-01-09
CVE-2024-21307 [HIGH] CWE-416 CVE-2024-21307: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2020-0869P3HIGHCVSS 8.8v1803v1903+1 more2020-03-12
CVE-2020-0869 [HIGH] CVE-2020-0869: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0801, CVE-2020-0807, CVE-2020-0809.
nvd
CVE-2019-0688P3HIGHCVSS 7.5v1709v18032019-04-09
CVE-2019-0688 [HIGH] CWE-327 CVE-2019-0688: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles frag
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
nvd
CVE-2022-30140P3HIGHCVSS 7.5v20h2≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30140 [HIGH] CVE-2022-30140: Windows iSCSI Discovery Service Remote Code Execution Vulnerability
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2024-30022P3HIGHCVSS 7.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30022 [HIGH] CWE-197 CVE-2024-30022: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30024P3HIGHCVSS 7.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30024 [HIGH] CWE-197 CVE-2024-30024: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30023P3HIGHCVSS 7.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30023 [HIGH] CWE-197 CVE-2024-30023: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-26195P3HIGHCVSS 7.2fixed in 10.0.14393.6897≥ 10.0.14393.0, < 10.0.14393.68972024-04-09
CVE-2024-26195 [HIGH] CWE-122 CVE-2024-26195: DHCP Server Service Remote Code Execution Vulnerability
DHCP Server Service Remote Code Execution Vulnerability
nvd
CVE-2024-26202P3HIGHCVSS 7.2fixed in 10.0.14393.6897≥ 10.0.14393.0, < 10.0.14393.68972024-04-09
CVE-2024-26202 [HIGH] CWE-122 CVE-2024-26202: DHCP Server Service Remote Code Execution Vulnerability
DHCP Server Service Remote Code Execution Vulnerability
nvd
CVE-2025-32713P3HIGHCVSS 7.8fixed in 10.0.14393.8148≥ 10.0.14393.0, < 10.0.14393.81482025-06-10
CVE-2025-32713 [HIGH] CWE-122 CVE-2025-32713: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd