cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 82 of 227
CVE-2021-36967P3HIGHCVSS 8.8v20h2v2004+1 more2021-09-15
CVE-2021-36967 [HIGH] CWE-269 CVE-2021-36967: Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21989P3HIGHCVSS 7.8≥ 10.0.14393.0, < 10.0.14393.49462022-02-09
CVE-2022-21989 [HIGH] CVE-2022-21989: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-37967P3HIGHCVSS 7.2≥ 10.0.14393.0, < 10.0.14393.63512022-11-09
CVE-2022-37967 [HIGH] CVE-2022-37967: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2019-0909P3HIGHCVSS 7.5v1803v1903+1 more2019-06-12
CVE-2019-0909 [HIGH] CVE-2019-0909: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2025-48822P3HIGHCVSS 8.6fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-48822 [HIGH] CWE-125 CVE-2025-48822: Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50507P3MEDIUMCVSS 6.8fixed in 10.0.14393.9234≥ 10.0.14393.0, < 10.0.14393.92342026-06-09
CVE-2026-50507 [MEDIUM] CWE-306 CVE-2026-50507: Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2020-16939P3HIGHCVSS 7.8v1903v1909+2 more2020-10-16
CVE-2020-16939 [HIGH] CWE-59 CVE-2020-16939: <p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An att An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affecte
nvd
CVE-2024-49019P3HIGHCVSS 7.8fixed in 10.0.14393.7515≥ 10.0.14393.0, < 10.0.14393.75152024-11-12
CVE-2024-49019 [HIGH] CWE-1390 CVE-2024-49019: Active Directory Certificate Services Elevation of Privilege Vulnerability Active Directory Certificate Services Elevation of Privilege Vulnerability
nvd
CVE-2022-35793P3HIGHCVSS 7.3v20h2≥ 10.0.14393.0, < 10.0.14393.52912022-08-09
CVE-2022-35793 [HIGH] CVE-2022-35793: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-26931P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.51252022-05-10
CVE-2022-26931 [HIGH] CVE-2022-26931: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-38062P3HIGHCVSS 7.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38062 [HIGH] CWE-125 CVE-2024-38062: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-28315P3HIGHCVSS 7.8v20h2v1909+2 more2021-04-13
CVE-2021-28315 [HIGH] CVE-2021-28315: Windows Media Video Decoder Remote Code Execution Vulnerability Windows Media Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2022-30209P3HIGHCVSS 7.4v20h2≥ 10.0.14393.0, < 10.0.14393.52462022-07-12
CVE-2022-30209 [HIGH] CVE-2022-30209: Windows IIS Server Elevation of Privilege Vulnerability Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2025-27470P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27470 [HIGH] CWE-400 CVE-2025-27470: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26652P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-26652 [HIGH] CWE-400 CVE-2025-26652: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27479P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27479 [HIGH] CWE-410 CVE-2025-27479: Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21174P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-21174 [HIGH] CWE-400 CVE-2025-21174: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27486P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27486 [HIGH] CWE-400 CVE-2025-27486: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27485P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-27485 [HIGH] CWE-400 CVE-2025-27485: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26680P3HIGHCVSS 7.5fixed in 10.0.14393.7969≥ 10.0.14393.0, < 10.0.14393.79692025-04-08
CVE-2025-26680 [HIGH] CWE-400 CVE-2025-26680: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase