cbcvebase.

Microsoft Windows Server 2016 vulnerabilities

4,536 known vulnerabilities affecting microsoft/windows_server_2016.

Total CVEs
4,536
CISA KEV
116
actively exploited
Public exploits
172
Exploited in wild
176
Severity breakdown
CRITICAL135HIGH3181MEDIUM1198LOW22

Vulnerabilities

Page 94 of 227
CVE-2024-21434P3HIGHCVSS 7.8fixed in 10.0.14393.68972024-03-12
CVE-2024-21434 [HIGH] CWE-197 CVE-2024-21434: Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
nvd
CVE-2019-0965P3HIGHCVSS 7.6v1803v19032019-08-14
CVE-2019-0965 [HIGH] CWE-20 CVE-2019-0965: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary
nvd
CVE-2025-21358P3HIGHCVSS 7.8fixed in 10.0.14393.7785≥ 10.0.14393.0, < 10.0.14393.77852025-02-11
CVE-2025-21358 [HIGH] CWE-822 CVE-2025-21358: Windows Core Messaging Elevation of Privileges Vulnerability Windows Core Messaging Elevation of Privileges Vulnerability
nvd
CVE-2024-43626P3HIGHCVSS 7.8fixed in 10.0.14393.7515≥ 10.0.14393.0, < 10.0.14393.75152024-11-12
CVE-2024-43626 [HIGH] CWE-122 CVE-2024-43626: Windows Telephony Service Elevation of Privilege Vulnerability Windows Telephony Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43556P3HIGHCVSS 7.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43556 [HIGH] CWE-416 CVE-2024-43556: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38050P3HIGHCVSS 7.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38050 [HIGH] CWE-191 CVE-2024-38050: Windows Workstation Service Elevation of Privilege Vulnerability Windows Workstation Service Elevation of Privilege Vulnerability
nvd
CVE-2024-30049P3HIGHCVSS 7.8fixed in 10.0.14393.6981≥ 10.0.14393.0, < 10.0.14393.69812024-05-14
CVE-2024-30049 [HIGH] CWE-416 CVE-2024-30049: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-38079P3HIGHCVSS 7.8fixed in 10.0.14393.7159≥ 10.0.14393.0, < 10.0.14393.71592024-07-09
CVE-2024-38079 [HIGH] CWE-122 CVE-2024-38079: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38250P3HIGHCVSS 7.8fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38250 [HIGH] CWE-126 CVE-2024-38250: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38247P3HIGHCVSS 7.8fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38247 [HIGH] CWE-415 CVE-2024-38247: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2025-49689P3HIGHCVSS 7.8fixed in 10.0.14393.8246≥ 10.0.14393.0, < 10.0.14393.82462025-07-08
CVE-2025-49689 [HIGH] CWE-125 CVE-2025-49689: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevat Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2022-37978P3HIGHCVSS 7.5≥ 10.0.14393.0, < 10.0.14393.54272022-10-11
CVE-2022-37978 [HIGH] CVE-2022-37978: Windows Active Directory Certificate Services Security Feature Bypass Windows Active Directory Certificate Services Security Feature Bypass
nvd
CVE-2024-43509P3HIGHCVSS 7.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43509 [HIGH] CWE-416 CVE-2024-43509: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-38141P3HIGHCVSS 7.8fixed in 10.0.14393.6252≥ 10.0.14393.0, < 10.0.14393.62522023-09-12
CVE-2023-38141 [HIGH] CWE-367 CVE-2023-38141: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43516P3HIGHCVSS 7.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.75152024-10-08
CVE-2024-43516 [HIGH] CWE-822 CVE-2024-43516: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-38142P3HIGHCVSS 7.8fixed in 10.0.14393.7259≥ 10.0.14393.0, < 10.0.14393.72592024-08-13
CVE-2024-38142 [HIGH] CWE-122 CVE-2024-38142: Windows Secure Kernel Mode Elevation of Privilege Vulnerability Windows Secure Kernel Mode Elevation of Privilege Vulnerability
nvd
CVE-2024-43514P3HIGHCVSS 7.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-43514 [HIGH] CWE-415 CVE-2024-43514: Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-38252P3HIGHCVSS 7.8fixed in 10.0.14393.7336≥ 10.0.14393.0, < 10.0.14393.73362024-09-10
CVE-2024-38252 [HIGH] CWE-416 CVE-2024-38252: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-37979P3HIGHCVSS 7.8fixed in 10.0.14393.7428≥ 10.0.14393.0, < 10.0.14393.74282024-10-08
CVE-2024-37979 [HIGH] CWE-822 CVE-2024-37979: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-21378P3HIGHCVSS 7.8fixed in 10.0.14393.7699≥ 10.0.14393.0, < 10.0.14393.76992025-01-14
CVE-2025-21378 [HIGH] CWE-122 CVE-2025-21378: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2016 vulnerabilities | cvebase