Windows Server 2016
by Microsoft
CVEs (5,103)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-8475 | Med | 0.33 | 5.0 | 0.04 | Jun 15, 2017 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects… | ||
| CVE-2017-8474 | Med | 0.33 | 5.0 | 0.04 | Jun 15, 2017 | The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application.… | ||
| CVE-2017-0297 | Med | 0.33 | 5.0 | 0.04 | Jun 15, 2017 | The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application.… | ||
| CVE-2017-0118 | Med | 0.33 | 4.3 | 0.23 | Mar 17, 2017 | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from… | ||
| CVE-2024-20662 | Med | 0.32 | 4.9 | 0.02 | Jan 9, 2024 | Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability | ||
| CVE-2021-41337 | Med | 0.32 | 4.9 | 0.02 | Oct 13, 2021 | Active Directory Security Feature Bypass Vulnerability | ||
| CVE-2020-1267 | Med | 0.32 | 4.9 | 0.05 | Jul 14, 2020 | This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'. | ||
| CVE-2019-1292 | Med | 0.32 | 4.9 | 0.05 | Sep 11, 2019 | A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. | ||
| CVE-2017-0190 | Med | 0.32 | 4.4 | 0.43 | May 12, 2017 | The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a… | ||
| CVE-2026-33829 | Med | 0.31 | 4.3 | 0.03 | Apr 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-58719 | Med | 0.31 | 4.7 | 0.00 | Oct 14, 2025 | Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-54101 | Med | 0.31 | 4.8 | 0.03 | Sep 9, 2025 | Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. | ||
| CVE-2024-43456 | Med | 0.31 | 4.8 | 0.01 | Oct 8, 2024 | Windows Remote Desktop Services Tampering Vulnerability | ||
| CVE-2024-30071 | Med | 0.31 | 4.7 | 0.01 | Jul 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-30069 | Med | 0.31 | 4.7 | 0.01 | Jun 11, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | ||
| CVE-2024-20691 | Med | 0.31 | 4.7 | 0.01 | Jan 9, 2024 | Windows Themes Information Disclosure Vulnerability | ||
| CVE-2023-20569 | Med | 0.31 | 4.7 | 0.07 | Aug 8, 2023 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | ||
| CVE-2023-32019 | Med | 0.31 | 4.7 | 0.01 | Jun 14, 2023 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2023-21766 | Med | 0.31 | 4.7 | 0.01 | Jan 10, 2023 | Windows Overlay Filter Information Disclosure Vulnerability | ||
| CVE-2022-34704 | Med | 0.31 | 4.7 | 0.01 | Aug 9, 2022 | Windows Defender Credential Guard Information Disclosure Vulnerability |
- risk 0.33cvss 5.0epss 0.04
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects…
- risk 0.33cvss 5.0epss 0.04
The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application.…
- risk 0.33cvss 5.0epss 0.04
The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application.…
- risk 0.33cvss 4.3epss 0.23
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from…
- risk 0.32cvss 4.9epss 0.02
Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
- risk 0.32cvss 4.9epss 0.02
Active Directory Security Feature Bypass Vulnerability
- risk 0.32cvss 4.9epss 0.05
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'.
- risk 0.32cvss 4.9epss 0.05
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
- risk 0.32cvss 4.4epss 0.43
The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a…
- risk 0.31cvss 4.3epss 0.03
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
- risk 0.31cvss 4.7epss 0.00
Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.
- risk 0.31cvss 4.8epss 0.03
Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
- risk 0.31cvss 4.8epss 0.01
Windows Remote Desktop Services Tampering Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Remote Access Connection Manager Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Themes Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.07
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
- risk 0.31cvss 4.7epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Overlay Filter Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Windows Defender Credential Guard Information Disclosure Vulnerability
Page 236 of 256