Windows Server 2016
by Microsoft
CVEs (5,109)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-7255 | Hig | 0.72 | 7.8 | 0.81 | KEV | Nov 10, 2016 | The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted… | |
| CVE-2026-21510 | Hig | 0.71 | 8.8 | 0.26 | KEV | Feb 10, 2026 | Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2023-24941 | Cri | 0.71 | 9.8 | 0.95 | May 9, 2023 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2022-41128 | Hig | 0.71 | 8.8 | 0.25 | KEV | Nov 9, 2022 | Windows Scripting Languages Remote Code Execution Vulnerability | |
| CVE-2022-26809 | Cri | 0.71 | 9.8 | 0.91 | Apr 15, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2020-1040 | Cri | 0.71 | 9.0 | 0.07 | KEV | Jul 14, 2020 | A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from… | |
| CVE-2019-0903 | Hig | 0.71 | 8.8 | 0.22 | KEV | May 16, 2019 | A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | |
| CVE-2026-41089 | Cri | 0.70 | 9.8 | 0.80 | May 12, 2026 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-21513 | Hig | 0.70 | 8.8 | 0.15 | KEV | Feb 10, 2026 | Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2025-29824 | Hig | 0.70 | 7.8 | 0.14 | KEV | Apr 8, 2025 | Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-21298 | Cri | 0.70 | 9.8 | 0.81 | Jan 14, 2025 | Windows OLE Remote Code Execution Vulnerability | ||
| CVE-2024-38077 | Cri | 0.70 | 9.8 | 0.75 | Jul 9, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | ||
| CVE-2024-30040 | Hig | 0.70 | 8.8 | 0.04 | KEV | May 14, 2024 | Windows MSHTML Platform Security Feature Bypass Vulnerability | |
| CVE-2023-32049 | Hig | 0.70 | 8.8 | 0.04 | KEV | Jul 11, 2023 | Windows SmartScreen Security Feature Bypass Vulnerability | |
| CVE-2023-23376 | Hig | 0.70 | 7.8 | 0.11 | KEV | Feb 14, 2023 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | |
| CVE-2022-34721 | Cri | 0.70 | 9.8 | 0.79 | Sep 13, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-30136 | Cri | 0.70 | 9.8 | 0.75 | Jun 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2022-26937 | Cri | 0.70 | 9.8 | 0.77 | May 10, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2019-1181 | Cri | 0.70 | 9.8 | 0.76 | Aug 14, 2019 | A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and… | ||
| CVE-2018-8639 | Hig | 0.70 | 7.8 | 0.22 | KEV | Dec 12, 2018 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… |
- risk 0.72cvss 7.8epss 0.81
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted…
- risk 0.71cvss 8.8epss 0.26
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.71cvss 9.8epss 0.95
Windows Network File System Remote Code Execution Vulnerability
- risk 0.71cvss 8.8epss 0.25
Windows Scripting Languages Remote Code Execution Vulnerability
- risk 0.71cvss 9.8epss 0.91
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.71cvss 9.0epss 0.07
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from…
- risk 0.71cvss 8.8epss 0.22
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
- risk 0.70cvss 9.8epss 0.80
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
- risk 0.70cvss 8.8epss 0.15
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.70cvss 7.8epss 0.14
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- risk 0.70cvss 9.8epss 0.81
Windows OLE Remote Code Execution Vulnerability
- risk 0.70cvss 9.8epss 0.75
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- risk 0.70cvss 8.8epss 0.04
Windows MSHTML Platform Security Feature Bypass Vulnerability
- risk 0.70cvss 8.8epss 0.04
Windows SmartScreen Security Feature Bypass Vulnerability
- risk 0.70cvss 7.8epss 0.11
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- risk 0.70cvss 9.8epss 0.79
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.70cvss 9.8epss 0.75
Windows Network File System Remote Code Execution Vulnerability
- risk 0.70cvss 9.8epss 0.77
Windows Network File System Remote Code Execution Vulnerability
- risk 0.70cvss 9.8epss 0.76
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and…
- risk 0.70cvss 7.8epss 0.22
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…
Page 3 of 256