Windows Server 2016
by Microsoft
CVEs (5,109)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1117 | Hig | 0.62 | 8.8 | 0.24 | Jul 15, 2019 | A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,… | ||
| CVE-2024-43451 | Med | 0.61 | 6.5 | 0.84 | KEV | Nov 12, 2024 | NTLM Hash Disclosure Spoofing Vulnerability | |
| CVE-2022-26904 | Hig | 0.61 | 7.0 | 0.10 | KEV | Apr 15, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability | |
| CVE-2021-34481 | Hig | 0.61 | 8.8 | 0.48 | Jul 16, 2021 | A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;… | ||
| CVE-2021-31962 | Cri | 0.61 | 9.4 | 0.04 | Jun 8, 2021 | Kerberos AppContainer Security Feature Bypass Vulnerability | ||
| CVE-2021-24093 | Hig | 0.61 | 8.8 | 0.44 | Feb 25, 2021 | Windows Graphics Component Remote Code Execution Vulnerability | ||
| CVE-2019-1152 | Hig | 0.61 | 8.8 | 0.13 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2019-1151 | Hig | 0.61 | 8.8 | 0.15 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2019-1149 | Hig | 0.61 | 8.8 | 0.14 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2019-1145 | Hig | 0.61 | 8.8 | 0.13 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2019-1144 | Hig | 0.61 | 8.8 | 0.13 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,… | ||
| CVE-2018-8420 | Hig | 0.61 | 8.8 | 0.49 | Sep 13, 2018 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012,… | ||
| CVE-2025-53778 | Hig | 0.60 | 8.8 | 0.38 | Aug 12, 2025 | Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-38144 | Hig | 0.60 | 8.8 | 0.32 | Aug 13, 2024 | Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | ||
| CVE-2023-35628 | Hig | 0.60 | 8.1 | 0.93 | Dec 12, 2023 | Windows MSHTML Platform Remote Code Execution Vulnerability | ||
| CVE-2023-28231 | Hig | 0.60 | 8.8 | 0.37 | Apr 11, 2023 | DHCP Server Service Remote Code Execution Vulnerability | ||
| CVE-2022-41076 | Hig | 0.60 | 8.5 | 0.62 | Dec 13, 2022 | PowerShell Remote Code Execution Vulnerability | ||
| CVE-2022-37958 | Hig | 0.60 | 8.1 | 0.86 | Sep 13, 2022 | SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | ||
| CVE-2022-24500 | Hig | 0.60 | 8.8 | 0.37 | Apr 15, 2022 | Windows SMB Remote Code Execution Vulnerability | ||
| CVE-2020-1301 | Hig | 0.60 | 8.8 | 0.37 | Jun 9, 2020 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. |
- risk 0.62cvss 8.8epss 0.24
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE-2019-1122, CVE-2019-1123,…
- risk 0.61cvss 6.5epss 0.84
NTLM Hash Disclosure Spoofing Vulnerability
- risk 0.61cvss 7.0epss 0.10
Windows User Profile Service Elevation of Privilege Vulnerability
- risk 0.61cvss 8.8epss 0.48
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;…
- risk 0.61cvss 9.4epss 0.04
Kerberos AppContainer Security Feature Bypass Vulnerability
- risk 0.61cvss 8.8epss 0.44
Windows Graphics Component Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.13
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.15
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.14
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.13
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.13
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view,…
- risk 0.61cvss 8.8epss 0.49
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012,…
- risk 0.60cvss 8.8epss 0.38
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- risk 0.60cvss 8.8epss 0.32
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
- risk 0.60cvss 8.1epss 0.93
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.60cvss 8.8epss 0.37
DHCP Server Service Remote Code Execution Vulnerability
- risk 0.60cvss 8.5epss 0.62
PowerShell Remote Code Execution Vulnerability
- risk 0.60cvss 8.1epss 0.86
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
- risk 0.60cvss 8.8epss 0.37
Windows SMB Remote Code Execution Vulnerability
- risk 0.60cvss 8.8epss 0.37
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
Page 13 of 256