Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 71 of 227
CVE-2025-26673P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-26673 [HIGH] CWE-400 CVE-2025-26673: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-36718P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.63512023-10-10
CVE-2023-36718 [HIGH] CWE-94 CVE-2023-36718: Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability
Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability
nvd
CVE-2025-27469P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27469 [HIGH] CWE-400 CVE-2025-27469: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2018-0956P3HIGHCVSS 7.5v1709v(Server Core installation)2018-04-12
CVE-2018-0956 [HIGH] CVE-2018-0956: A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys imp
A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2022-24545P3HIGHCVSS 7.5v20h2≥ 10.0.14393.0, < 10.0.14393.50662022-04-15
CVE-2022-24545 [HIGH] CVE-2022-24545: Windows Kerberos Remote Code Execution Vulnerability
Windows Kerberos Remote Code Execution Vulnerability
nvd
CVE-2020-1401P3HIGHCVSS 7.8v1903v1909+1 more2020-07-14
CVE-2020-1401 [HIGH] CVE-2020-1401: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1407.
nvd
CVE-2025-47972P3HIGHCVSS 8.0fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-47972 [HIGH] CWE-362 CVE-2025-47972: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-30149P3HIGHCVSS 7.5v20h2≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30149 [HIGH] CVE-2022-30149: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30143P3HIGHCVSS 7.5v20h2≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30143 [HIGH] CVE-2022-30143: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30146P3HIGHCVSS 7.5v20h2≥ 10.0.14393.0, < 10.0.14393.51922022-06-15
CVE-2022-30146 [HIGH] CVE-2022-30146: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2025-49691P3HIGHCVSS 8.0fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49691 [HIGH] CWE-122 CVE-2025-49691: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-47955P3HIGHCVSS 7.8fixed in 10.0.14393.8066≥ 10.0.14393.0, < 10.0.14393.80662025-06-10
CVE-2025-47955 [HIGH] CWE-269 CVE-2025-47955: Improper privilege management in Windows Remote Access Connection Manager allows an authorized attac
Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26686P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-26686 [HIGH] CWE-591 CVE-2025-26686: Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker
Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-30015P3HIGHCVSS 7.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30015 [HIGH] CWE-197 CVE-2024-30015: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30029P3HIGHCVSS 7.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30029 [HIGH] CWE-197 CVE-2024-30029: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30014P3HIGHCVSS 7.5fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30014 [HIGH] CWE-197 CVE-2024-30014: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2018-8251P3HIGHCVSS 7.5v1709v1803+1 more2018-06-14
CVE-2018-8251 [HIGH] CWE-787 CVE-2018-8251: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media Foundation Memory Corruption Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2026-20846P3HIGHCVSS 7.5fixed in 10.0.14393.8868≥ 10.0.14393.0, < 10.0.14393.88682026-02-10
CVE-2026-20846 [HIGH] CWE-126 CVE-2026-20846: Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
nvd
CVE-2018-0965P3HIGHCVSS 8.4v1709v1803+1 more2018-09-13
CVE-2018-0965 [HIGH] CWE-20 CVE-2018-0965: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8439.
nvd
CVE-2025-62455P3HIGHCVSS 7.8fixed in 10.0.14393.8688≥ 10.0.14393.0, < 10.0.14393.86882025-12-09
CVE-2025-62455 [HIGH] CWE-20 CVE-2025-62455: Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privil
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd