cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 106 of 201
CVE-2017-8720P3HIGHCVSS 7.8vr22017-09-13
CVE-2017-8720 [HIGH] CVE-2017-8720: The Microsoft Windows graphics component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 The Microsoft Windows graphics component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when the Win32k component fails to properly handle objects in memory, aka "Win32k Eleva
nvd
CVE-2016-7260P3HIGHCVSS 7.8vr22016-12-20
CVE-2016-7260 [HIGH] CWE-264 CVE-2016-7260: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2018-8164P3HIGHCVSS 7.8vr22018-05-09
CVE-2018-8164 [HIGH] CVE-2018-8164: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows
nvd
CVE-2016-3305P3HIGHCVSS 7.8vr22016-09-14
CVE-2016-3305 [HIGH] CWE-19 CVE-2016-3305: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessions, and consequently gain privileges, via a crafted application, aka "Windows Session Object El
nvd
CVE-2022-21901P3HIGHCVSS 8.0vr22022-01-11
CVE-2022-21901 [HIGH] CVE-2022-21901: Windows Hyper-V Elevation of Privilege Vulnerability Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2020-16920P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2020-10-16
CVE-2020-16920 [HIGH] CVE-2020-16920: <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a spec
nvd
CVE-2017-0056P3HIGHCVSS 7.8vr22017-03-17
CVE-2017-0056 [HIGH] CVE-2017-0056: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." This vulnerability is d
nvd
CVE-2022-30166P3HIGHCVSS 7.8≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30166 [HIGH] CVE-2022-30166: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2025-21220P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21220 [HIGH] CWE-908 CVE-2025-21220: Microsoft Message Queuing Information Disclosure Vulnerability Microsoft Message Queuing Information Disclosure Vulnerability
nvd
CVE-2023-36567P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.245232023-10-10
CVE-2023-36567 [HIGH] CWE-908 CVE-2023-36567: Windows Deployment Services Information Disclosure Vulnerability Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2020-1070P3HIGHCVSS 7.8vr22020-05-21
CVE-2020-1070 [HIGH] CVE-2020-1070: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system, aka 'Windows Print Spooler Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1048.
nvd
CVE-2021-1648P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-01-12
CVE-2021-1648 [HIGH] CWE-269 CVE-2021-1648: Microsoft splwow64 Elevation of Privilege Vulnerability Microsoft splwow64 Elevation of Privilege Vulnerability
nvd
CVE-2023-36906P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.244142023-08-08
CVE-2023-36906 [HIGH] CWE-170 CVE-2023-36906: Windows Cryptographic Services Information Disclosure Vulnerability Windows Cryptographic Services Information Disclosure Vulnerability
nvd
CVE-2021-26862P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-03-11
CVE-2021-26862 [HIGH] CWE-59 CVE-2021-26862: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1475P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2020-08-17
CVE-2020-1475 [HIGH] CVE-2020-1475: An elevation of privilege vulnerability exists in the way that the srmsvc.dll handles objects in mem An elevation of privilege vulnerability exists in the way that the srmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability b
nvd
CVE-2022-38004P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-38004 [HIGH] CVE-2022-38004: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2020-17092P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < publication2020-12-10
CVE-2020-17092 [HIGH] CVE-2020-17092: Windows Network Connections Service Elevation of Privilege Vulnerability Windows Network Connections Service Elevation of Privilege Vulnerability
nvd
CVE-2019-0973P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < publication2019-06-12
CVE-2019-0973 [HIGH] CWE-20 CVE-2019-0973: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new
nvd
CVE-2022-41121P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.240182022-12-13
CVE-2022-41121 [HIGH] CVE-2022-41121: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-34719P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34719 [HIGH] CVE-2022-34719: Windows Distributed File System (DFS) Elevation of Privilege Vulnerability Windows Distributed File System (DFS) Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase