Windows Server 2016
by Microsoft
CVEs (5,109)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33745 | Med | 0.42 | 6.5 | 0.03 | Jul 14, 2021 | Windows DNS Server Denial of Service Vulnerability | ||
| CVE-2021-31959 | Med | 0.42 | 6.4 | 0.09 | Jun 8, 2021 | Scripting Engine Memory Corruption Vulnerability | ||
| CVE-2021-31205 | Med | 0.42 | 6.5 | 0.03 | May 11, 2021 | Windows SMB Client Security Feature Bypass Vulnerability | ||
| CVE-2021-28441 | Med | 0.42 | 6.5 | 0.01 | Apr 13, 2021 | Windows Hyper-V Information Disclosure Vulnerability | ||
| CVE-2021-28328 | Med | 0.42 | 6.5 | 0.02 | Apr 13, 2021 | Windows DNS Information Disclosure Vulnerability | ||
| CVE-2021-28311 | Med | 0.42 | 6.5 | 0.03 | Apr 13, 2021 | Windows Application Compatibility Cache Denial of Service Vulnerability | ||
| CVE-2021-24080 | Med | 0.42 | 6.5 | 0.03 | Feb 25, 2021 | Windows Trust Verification API Denial of Service Vulnerability | ||
| CVE-2020-16996 | Med | 0.42 | 6.5 | 0.02 | Dec 10, 2020 | Kerberos Security Feature Bypass Vulnerability | ||
| CVE-2020-17040 | Med | 0.42 | 6.5 | 0.03 | Nov 11, 2020 | Windows Hyper-V Security Feature Bypass Vulnerability | ||
| CVE-2020-0904 | Med | 0.42 | 6.5 | 0.01 | Sep 11, 2020 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest… | ||
| CVE-2020-0890 | Med | 0.42 | 6.5 | 0.03 | Sep 11, 2020 | A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest… | ||
| CVE-2020-15706 | Med | 0.42 | 6.4 | 0.01 | Jul 29, 2020 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This… | ||
| CVE-2020-15705 | Med | 0.42 | 6.4 | 0.01 | Jul 29, 2020 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without… | ||
| CVE-2019-1198 | Med | 0.42 | 6.5 | 0.02 | Aug 14, 2019 | An elevation of privilege exists in SyncController.dll. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the… | ||
| CVE-2019-1043 | Med | 0.42 | 6.4 | 0.03 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the… | ||
| CVE-2017-0174 | Med | 0.42 | 6.5 | 0.03 | Aug 8, 2017 | Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles NetBIOS packets, aka… | ||
| CVE-2024-28898 | Med | 0.41 | 6.3 | 0.01 | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2022-21928 | Med | 0.41 | 6.3 | 0.01 | Jan 11, 2022 | Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | ||
| CVE-2021-34500 | Med | 0.41 | 6.3 | 0.03 | Jul 14, 2021 | Windows Kernel Memory Information Disclosure Vulnerability | ||
| CVE-2021-33755 | Med | 0.41 | 6.3 | 0.03 | Jul 14, 2021 | Windows Hyper-V Denial of Service Vulnerability |
- risk 0.42cvss 6.5epss 0.03
Windows DNS Server Denial of Service Vulnerability
- risk 0.42cvss 6.4epss 0.09
Scripting Engine Memory Corruption Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows SMB Client Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.01
Windows Hyper-V Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows DNS Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Application Compatibility Cache Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Trust Verification API Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Kerberos Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Hyper-V Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.01
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest…
- risk 0.42cvss 6.5epss 0.03
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest…
- risk 0.42cvss 6.4epss 0.01
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This…
- risk 0.42cvss 6.4epss 0.01
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without…
- risk 0.42cvss 6.5epss 0.02
An elevation of privilege exists in SyncController.dll. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the…
- risk 0.42cvss 6.4epss 0.03
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
- risk 0.42cvss 6.5epss 0.03
Windows NetBIOS in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it improperly handles NetBIOS packets, aka…
- risk 0.41cvss 6.3epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.41cvss 6.3epss 0.01
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
- risk 0.41cvss 6.3epss 0.03
Windows Kernel Memory Information Disclosure Vulnerability
- risk 0.41cvss 6.3epss 0.03
Windows Hyper-V Denial of Service Vulnerability
Page 196 of 256