Windows Server 2016
by Microsoft
CVEs (5,109)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-0182 | Med | 0.38 | 5.8 | 0.04 | Apr 12, 2017 | A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating… | ||
| CVE-2017-0179 | Med | 0.38 | 5.8 | 0.04 | Apr 12, 2017 | A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service… | ||
| CVE-2026-23670 | Med | 0.37 | 5.7 | 0.00 | Apr 14, 2026 | Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2025-53719 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53153 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53148 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53138 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-50157 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-50156 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-49722 | Med | 0.37 | 5.7 | 0.01 | Jul 8, 2025 | Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network. | ||
| CVE-2025-29974 | Med | 0.37 | 5.7 | 0.01 | May 13, 2025 | Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network. | ||
| CVE-2024-26209 | Med | 0.37 | 5.5 | 0.15 | Apr 9, 2024 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | ||
| CVE-2024-21430 | Med | 0.37 | 5.7 | 0.01 | Mar 12, 2024 | Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability | ||
| CVE-2024-20692 | Med | 0.37 | 5.7 | 0.01 | Jan 9, 2024 | Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | ||
| CVE-2023-20588 | Med | 0.37 | 5.5 | 0.11 | Aug 8, 2023 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | ||
| CVE-2023-21693 | Med | 0.37 | 5.7 | 0.01 | Feb 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2022-30223 | Med | 0.37 | 5.7 | 0.01 | Jul 12, 2022 | Windows Hyper-V Information Disclosure Vulnerability | ||
| CVE-2022-22711 | Med | 0.37 | 5.7 | 0.01 | Jul 12, 2022 | Windows BitLocker Information Disclosure Vulnerability | ||
| CVE-2021-42288 | Med | 0.37 | 5.7 | 0.01 | Nov 10, 2021 | Windows Hello Security Feature Bypass Vulnerability | ||
| CVE-2021-38632 | Med | 0.37 | 5.7 | 0.01 | Sep 15, 2021 | Windows BitLocker Security Feature Bypass Vulnerability |
- risk 0.38cvss 5.8epss 0.04
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating…
- risk 0.38cvss 5.8epss 0.04
A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service…
- risk 0.37cvss 5.7epss 0.00
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network.
- risk 0.37cvss 5.7epss 0.01
Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.
- risk 0.37cvss 5.5epss 0.15
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability
- risk 0.37cvss 5.7epss 0.01
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
- risk 0.37cvss 5.5epss 0.11
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
- risk 0.37cvss 5.7epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows Hyper-V Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows BitLocker Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows Hello Security Feature Bypass Vulnerability
- risk 0.37cvss 5.7epss 0.01
Windows BitLocker Security Feature Bypass Vulnerability
Page 203 of 256