Windows Server 2016
by Microsoft
CVEs (5,109)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-0164 | Med | 0.29 | 4.4 | 0.04 | Apr 12, 2017 | A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability." | ||
| CVE-2017-0154 | Med | 0.29 | 4.4 | 0.11 | Mar 17, 2017 | Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of… | ||
| CVE-2017-0057 | Med | 0.29 | 4.3 | 0.14 | Mar 17, 2017 | DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a workstation user to… | ||
| CVE-2026-20936 | Med | 0.28 | 4.3 | 0.00 | Jan 13, 2026 | Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack. | ||
| CVE-2025-54917 | Med | 0.28 | 4.3 | 0.01 | Sep 9, 2025 | Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-54107 | Med | 0.28 | 4.3 | 0.01 | Sep 9, 2025 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-24055 | Med | 0.28 | 4.3 | 0.01 | Mar 11, 2025 | Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. | ||
| CVE-2025-21247 | Med | 0.28 | 4.3 | 0.03 | Mar 11, 2025 | Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-21332 | Med | 0.28 | 4.3 | 0.01 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21329 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21328 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21269 | Med | 0.28 | 4.3 | 0.05 | Jan 14, 2025 | Windows HTML Platforms Security Feature Bypass Vulnerability | ||
| CVE-2025-21268 | Med | 0.28 | 4.3 | 0.02 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21219 | Med | 0.28 | 4.3 | 0.03 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2025-21189 | Med | 0.28 | 4.3 | 0.03 | Jan 14, 2025 | MapUrlToZone Security Feature Bypass Vulnerability | ||
| CVE-2024-29056 | Med | 0.28 | 4.3 | 0.01 | Apr 9, 2024 | Windows Authentication Elevation of Privilege Vulnerability | ||
| CVE-2023-21729 | Med | 0.28 | 4.3 | 0.01 | Apr 11, 2023 | Remote Procedure Call Runtime Information Disclosure Vulnerability | ||
| CVE-2023-24911 | Med | 0.28 | 4.3 | 0.01 | Mar 14, 2023 | Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | ||
| CVE-2022-37981 | Med | 0.28 | 4.3 | 0.02 | Oct 11, 2022 | Windows Event Logging Service Denial of Service Vulnerability | ||
| CVE-2021-24082 | Med | 0.28 | 4.3 | 0.03 | Feb 25, 2021 | Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability |
- risk 0.29cvss 4.4epss 0.04
A denial of service vulnerability exists in Windows 10 1607 and Windows Server 2016 Active Directory when an authenticated attacker sends malicious search queries, aka "Active Directory Denial of Service Vulnerability."
- risk 0.29cvss 4.4epss 0.11
Microsoft Internet Explorer 11 on Windows 10, 1511, and 1606 and Windows Server 2016 does not enforce cross-domain policies, allowing attackers to access information from one domain and inject it into another via a crafted application, aka, "Internet Explorer Elevation of…
- risk 0.29cvss 4.3epss 0.14
DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a workstation user to…
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
- risk 0.28cvss 4.3epss 0.01
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.01
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.01
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.
- risk 0.28cvss 4.3epss 0.03
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.28cvss 4.3epss 0.01
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.05
Windows HTML Platforms Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.03
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.03
MapUrlToZone Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.01
Windows Authentication Elevation of Privilege Vulnerability
- risk 0.28cvss 4.3epss 0.01
Remote Procedure Call Runtime Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.02
Windows Event Logging Service Denial of Service Vulnerability
- risk 0.28cvss 4.3epss 0.03
Microsoft.PowerShell.Utility Module WDAC Security Feature Bypass Vulnerability
Page 241 of 256