CVE Vulnerabilities for "product:windows_server_2016"

Showing 1-10 of 4,897 CVEs (filtered from 316,407 total)

Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.

HIGH 8.8
EPSS 0.1%
10/14/2025
2025

Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.

LOW 2.1
EPSS 0.1%
10/14/2025
2025
CVE-2025-59287
⚠️🧬

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CRITICAL 9.8
EPSS 9.4%
10/14/2025
2025

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

HIGH 7
EPSS 0.1%
10/14/2025
2025

Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.

LOW 3.1
EPSS 0.0%
10/14/2025
2025

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.1%
10/14/2025
2025

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.1%
10/14/2025
2025

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.1%
10/14/2025
2025

Exposure of sensitive information to an unauthorized actor in Microsoft Failover Cluster Virtual Driver allows an authorized attacker to disclose information locally.

MEDIUM 5.5
EPSS 0.1%
10/14/2025
2025

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

MEDIUM 6.5
EPSS 0.2%
10/14/2025
2025
Page 1 of 2