Microsoft Windows Server 2016 vulnerabilities
4,536 known vulnerabilities affecting microsoft/windows_server_2016.
Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
175
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22
Vulnerabilities
Page 9 of 227
CVE-2024-38063P1CRITICALCVSS 9.8PoCfixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38063 [CRITICAL] CWE-191 CVE-2024-38063: Windows TCP/IP Remote Code Execution Vulnerability
Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2018-8596P2MEDIUMCVSS 6.5Exploitedv1709v18032018-12-12
CVE-2018-8596 [MEDIUM] CVE-2018-8596: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2018-8595P2MEDIUMCVSS 6.5Exploitedv1709v1803+1 more2018-12-12
CVE-2018-8595 [MEDIUM] CVE-2018-8595: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2020-1206P2HIGHCVSS 7.5Exploitedv1903v1909+1 more2020-06-09
CVE-2020-1206 [HIGH] CWE-908 CVE-2020-1206: An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.
An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Information Disclosure Vulnerability'.
nvd
CVE-2018-8637P2MEDIUMCVSS 5.5Exploitedv18032018-12-12
CVE-2018-8637 [MEDIUM] CVE-2018-8637: An information disclosure vulnerability exists in Windows kernel that could allow an attacker to ret
An information disclosure vulnerability exists in Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (KASLR) bypass, aka "Win32k Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10, Windows Server 2019.
nvd
CVE-2018-8477P2MEDIUMCVSS 5.5Exploitedv1709v18032018-12-12
CVE-2018-8477 [MEDIUM] CVE-2018-8477: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows
nvd
CVE-2021-28442P2MEDIUMCVSS 6.5Exploitedv20h2v1909+1 more2021-04-13
CVE-2021-28442 [MEDIUM] CVE-2021-28442: Windows TCP/IP Information Disclosure Vulnerability
Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2019-0784P2HIGHCVSS 7.5Exploitedv1709v18032019-04-09
CVE-2019-0784 [HIGH] CWE-787 CVE-2019-0784: A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles
A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles objects in memory, aka 'Windows ActiveX Remote Code Execution Vulnerability'.
nvd
CVE-2022-21874P2CRITICALCVSS 9.8Exploited≥ 10.0.14393.0, < 10.0.14393.48862022-01-11
CVE-2022-21874 [CRITICAL] CVE-2022-21874: Windows Security Center API Remote Code Execution Vulnerability
Windows Security Center API Remote Code Execution Vulnerability
nvd
CVE-2018-8544P2HIGHCVSS 8.8PoCv1709v1803+1 more2018-11-14
CVE-2018-8544 [HIGH] CWE-416 CVE-2018-8544: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2018-0886P2HIGHCVSS 7.0PoCv1709v18032018-03-14
CVE-2018-0886 [HIGH] CWE-287 CVE-2018-0886: The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how CredSSP validates request
nvd
CVE-2019-1150P2HIGHCVSS 8.8PoCv1803v1903+1 more2019-08-14
CVE-2019-1150 [HIGH] CWE-787 CVE-2019-1150: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2023-24941P2CRITICALCVSS 9.8≥ 10.0.14393.0, < 10.0.14393.59212023-05-09
CVE-2023-24941 [CRITICAL] CWE-908 CVE-2023-24941: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2025-21293P2HIGHCVSS 8.8PoCfixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21293 [HIGH] CWE-284 CVE-2025-21293: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2024-38077P1CRITICALCVSS 9.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38077 [CRITICAL] CWE-122 CVE-2024-38077: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2019-1151P2HIGHCVSS 8.8PoCv1803v1903+1 more2019-08-14
CVE-2019-1151 [HIGH] CWE-787 CVE-2019-1151: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2024-49112P1CRITICALCVSS 9.8fixed in 10.0.14393.7606≥ 10.0.14393.0, < 10.0.14393.76062024-12-12
CVE-2024-49112 [CRITICAL] CWE-190 CVE-2024-49112: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2019-1181P2CRITICALCVSS 9.8v1803v1903+1 more2019-08-14
CVE-2019-1181 [CRITICAL] CVE-2019-1181: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability cou
nvd
CVE-2019-1118P2HIGHCVSS 8.8PoCv1803v19032019-07-15
CVE-2019-1118 [HIGH] CVE-2019-1118: A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory,
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
nvd
CVE-2019-1117P2HIGHCVSS 8.8PoCv1803v19032019-07-15
CVE-2019-1117 [HIGH] CVE-2019-1117: A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory,
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123, CVE-2019-1124, CVE-2019-1127, CVE-2019-1128.
nvd