cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 108 of 201
CVE-2020-1579P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2020-08-17
CVE-2020-1579 [HIGH] CVE-2020-1579: An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider imp An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correc
nvd
CVE-2020-1587P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2020-08-17
CVE-2020-1587 [HIGH] CVE-2020-1587: An elevation of privilege vulnerability exists when the Windows Ancillary Function Driver for WinSoc An elevation of privilege vulnerability exists when the Windows Ancillary Function Driver for WinSock improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by c
nvd
CVE-2022-24550P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-24550 [HIGH] CVE-2022-24550: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2023-28247P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28247 [HIGH] CWE-191 CVE-2023-28247: Windows Network File System Information Disclosure Vulnerability Windows Network File System Information Disclosure Vulnerability
nvd
CVE-2020-1254P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1254 [HIGH] CVE-2020-1254: An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly han An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly handles class object members.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Modules Installer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2021-40489P3HIGHCVSS 7.8vr2≥ 6.2.0, < 6.2.9200.234902021-10-13
CVE-2021-40489 [HIGH] CWE-269 CVE-2021-40489: Storage Spaces Controller Elevation of Privilege Vulnerability Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2021-40478P3HIGHCVSS 7.8vr2≥ 6.2.0, < 6.2.9200.234902021-10-13
CVE-2021-40478 [HIGH] CWE-269 CVE-2021-40478: Storage Spaces Controller Elevation of Privilege Vulnerability Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2021-41345P3HIGHCVSS 7.8vr2≥ 6.2.0, < 6.2.9200.234902021-10-13
CVE-2021-41345 [HIGH] CWE-269 CVE-2021-41345: Storage Spaces Controller Elevation of Privilege Vulnerability Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2020-1538P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2020-08-17
CVE-2020-1538 [HIGH] CVE-2020-1538: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how the Wind
nvd
CVE-2020-1517P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2020-08-17
CVE-2020-1517 [HIGH] CVE-2020-1517: An elevation of privilege vulnerability exists when the Windows File Server Resource Management Serv An elevation of privilege vulnerability exists when the Windows File Server Resource Management Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by
nvd
CVE-2020-1488P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2020-08-17
CVE-2020-1488 [HIGH] CWE-269 CVE-2020-1488: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files. To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges. The security update addresses the vulnerability by corr
nvd
CVE-2020-1430P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1430 [HIGH] CVE-2020-1430: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1354.
nvd
CVE-2020-1354P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1354 [HIGH] CVE-2020-1354: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows UPnP Device Host Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1430.
nvd
CVE-2020-0912P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-0912 [HIGH] CVE-2020-0912: <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correct
nvd
CVE-2023-21817P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.241162023-02-14
CVE-2023-21817 [HIGH] CWE-287 CVE-2023-21817: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2021-1652P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-01-12
CVE-2021-1652 [HIGH] CWE-269 CVE-2021-1652: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1653P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-01-12
CVE-2021-1653 [HIGH] CWE-269 CVE-2021-1653: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1693P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-01-12
CVE-2021-1693 [HIGH] CWE-269 CVE-2021-1693: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1654P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-01-12
CVE-2021-1654 [HIGH] CWE-269 CVE-2021-1654: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1655P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-01-12
CVE-2021-1655 [HIGH] CWE-269 CVE-2021-1655: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase