Msrc Windows Server 2016 vulnerabilities
4,120 known vulnerabilities affecting msrc/windows_server_2016.
Total CVEs
4,120
CISA KEV
154
actively exploited
Public exploits
204
Exploited in wild
143
Severity breakdown
CRITICAL86HIGH2734MEDIUM1267LOW33
Vulnerabilities
Page 71 of 206
CVE-2023-35362HIGHCVSS 7.82023-07-11
CVE-2023-35362 [HIGH] CWE-591 Windows Clip Service Elevation of Privilege Vulnerability
Windows Clip Service Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
In this case, a successful attack could be performed from a low privilege AppContainer. The attacker could elevate their privileges and execute code or access resources at a higher integrity level than that of the
msrc
CVE-2023-35353HIGHCVSS 7.82023-07-11
CVE-2023-35353 [HIGH] CWE-59 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
Connected User Experiences and Telemetry Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Connected User Experiences and Telemetry: Windows Connected User Experiences and Telemetry
Microsoft: Microsoft
Cust
msrc
CVE-2023-35317HIGHCVSS 7.82023-07-11
CVE-2023-35317 [HIGH] CWE-502 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain administrator privileges.
Windows Server Update Service: Windows Server Update Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elev
msrc
CVE-2023-35302HIGHCVSS 8.82023-07-11
CVE-2023-35302 [HIGH] CWE-122 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An authenticated attacker with normal privileges could send a modified XPS file to a shared printer, which can result in a remote code execution.
Microsoft Printer Drivers: Microsoft Printer Drivers
Microsoft: Microsoft
Customer Action R
msrc
CVE-2023-35309HIGHCVSS 7.52023-07-11
CVE-2023-35309 [HIGH] CWE-591 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
To successfully exploit this vulnerability, the target server must be configured to allow remote activation of the COM object. In addition, the attacker must have sufficient user privileges on that server.
FAQ: According to the CVSS metric, the attack complexity is high (AC:
msrc
CVE-2023-32049HIGHCVSS 8.8KEV2023-07-11
CVE-2023-32049 [HIGH] Windows SmartScreen Security Feature Bypass Vulnerability
Windows SmartScreen Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
The attacker would be able to bypass the Open File - Security Warning prompt.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be comp
msrc
CVE-2023-35356HIGHCVSS 7.82023-07-11
CVE-2023-35356 [HIGH] CWE-843 Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Kernel: Windows Kernel
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest So
msrc
CVE-2023-32038HIGHCVSS 8.82023-07-11
CVE-2023-32038 [HIGH] CWE-416 Microsoft ODBC Driver Remote Code Execution Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An attacker could exploit the vulnerability by tricking an authenticated user into attempting to connect to a malicious SQL server via ODBC, which could result in the server receiving a malicious networking packet. This could allow the attacker to execute code remotely on the client.
Windows ODBC
msrc
CVE-2023-35360HIGHCVSS 7.02023-07-11
CVE-2023-35360 [HIGH] CWE-591 Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an at
msrc
CVE-2023-35297HIGHCVSS 8.12023-07-11
CVE-2023-35297 [HIGH] CWE-843 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS score, the attack
msrc
CVE-2023-36884HIGHCVSS 7.5KEV2023-07-11
CVE-2023-36884 [HIGH] CWE-362 Windows Search Remote Code Execution Vulnerability
Windows Search Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to high loss of confidentiality (C:H), integrity (I:H) and availa
msrc
CVE-2023-33163HIGHCVSS 7.52023-07-11
CVE-2023-33163 [HIGH] CWE-591 Windows Network Load Balancing Remote Code Execution Vulnerability
Windows Network Load Balancing Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
Successf
msrc
CVE-2023-35357HIGHCVSS 7.82023-07-11
CVE-2023-35357 [HIGH] CWE-125 Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Kernel: Windows Kernel
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest So
msrc
CVE-2023-35322HIGHCVSS 8.82023-07-11
CVE-2023-35322 [HIGH] CWE-121 Windows Deployment Services Remote Code Execution Vulnerability
Windows Deployment Services Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
FAQ: How can attacker successfully exploit this vulnerability?
An attacker with user permissions could alter specific variables in the CNTCIR Packet of the WDSMA protocol in order to exploit this vulnerability. For more information about CNTCIR Packet see CNTCIR Packet.
Windows Deplo
msrc
CVE-2023-35338HIGHCVSS 7.52023-07-11
CVE-2023-35338 [HIGH] CWE-476 Windows Peer Name Resolution Protocol Denial of Service Vulnerability
Windows Peer Name Resolution Protocol Denial of Service Vulnerability
Windows Peer Name Resolution Protocol: Windows Peer Name Resolution Protocol
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search
msrc
CVE-2023-35339HIGHCVSS 7.52023-07-11
CVE-2023-35339 [HIGH] CWE-400 Windows CryptoAPI Denial of Service Vulnerability
Windows CryptoAPI Denial of Service Vulnerability
Windows CryptoAPI: Windows CryptoAPI
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference: https://support.microsoft.com/help/5028168
Refer
msrc
CVE-2023-35306MEDIUMCVSS 5.52023-07-11
CVE-2023-35306 [MEDIUM] CWE-20 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could view heap memory from a privileged process running on the server.
Microsoft Printer Drivers: Microsoft Printer Drivers
Microsoft: Microsoft
Customer Acti
msrc
CVE-2023-33172MEDIUMCVSS 6.52023-07-11
CVE-2023-33172 [MEDIUM] CWE-126 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc
CVE-2023-32035MEDIUMCVSS 6.52023-07-11
CVE-2023-32035 [MEDIUM] CWE-125 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc
CVE-2023-35314MEDIUMCVSS 6.52023-07-11
CVE-2023-35314 [MEDIUM] CWE-125 Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
Windows Remote Procedure Call: Windows Remote Procedure Call
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168
Reference:
msrc