cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 123 of 201
CVE-2024-21433P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.247682024-03-12
CVE-2024-21433 [HIGH] CWE-367 CVE-2024-21433: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2020-1287P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1287 [HIGH] CVE-2020-1287: An elevation of privilege vulnerability exists in the way that the Windows WalletService handles obj An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletService Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1294.
nvd
CVE-2020-1291P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1291 [HIGH] CVE-2020-1291: An elevation of privilege vulnerability exists in the way that the Windows Network Connections Servi An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1149P3HIGHCVSS 7.8vr22020-05-21
CVE-2020-1149 [HIGH] CVE-2020-1149: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1077, CVE-2020-1086, CVE-2020-1090, CVE-2020-1125, CVE-2020-1139, CVE-2020-1151, CVE-2020-1155, CVE-2020-1156, CVE-2020-1157, CVE-2020-1158, CVE-2020-1164.
nvd
CVE-2025-21181P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21181 [HIGH] CWE-400 CVE-2025-21181: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2017-0271P3MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0271 [MEDIUM] CVE-2017-0271: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2023-35638P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.246142023-12-12
CVE-2023-35638 [HIGH] CWE-126 CVE-2023-35638: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2020-1552P3HIGHCVSS 7.8vr22020-08-17
CVE-2020-1552 [HIGH] CVE-2020-1552: An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handl An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulner
nvd
CVE-2015-0089P3MEDIUMCVSS 5.0vr22015-03-11
CVE-2015-0089 [MEDIUM] CVE-2015-0089: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR protection mechanism, via a crafted font, ak
nvd
CVE-2017-11816P3MEDIUMCVSS 5.5vr22017-10-13
CVE-2017-11816 [MEDIUM] CWE-200 CVE-2017-11816: The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka "Windows GDI Inf
nvd
CVE-2019-0838P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0838 [HIGH] CVE-2019-0838: An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses cred An information disclosure vulnerability exists when Windows Task Scheduler improperly discloses credentials to Windows Credential Manager, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0839.
nvd
CVE-2017-0267P3MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0267 [MEDIUM] CWE-200 CVE-2017-0267: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclo
nvd
CVE-2015-1716P3MEDIUMCVSS 5.0vr22015-05-13
CVE-2015-1716 [MEDIUM] CWE-200 CVE-2015-1716: Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1 Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict Diffie-Hellman Ephemeral (DHE) key lengths, which makes it easier for remote attackers to defeat cryptographic protection me
nvd
CVE-2024-26215P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.248212024-04-09
CVE-2024-26215 [HIGH] CWE-400 CVE-2024-26215: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2020-0637P3MEDIUMCVSS 6.5vr22020-01-14
CVE-2020-0637 [MEDIUM] CVE-2020-0637: An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles cre An information disclosure vulnerability exists when Remote Desktop Web Access improperly handles credential information, aka 'Remote Desktop Web Access Information Disclosure Vulnerability'.
nvd
CVE-2025-21300P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21300 [HIGH] CWE-400 CVE-2025-21300: Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability
nvd
CVE-2015-1638P3MEDIUMCVSS 5.8vr22015-04-14
CVE-2015-1638 [MEDIUM] CWE-264 CVE-2015-1638: Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not proper Microsoft Active Directory Federation Services (AD FS) 3.0 on Windows Server 2012 R2 does not properly handle logoff actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation, aka "Active Directory Federation Services Information Disclosure Vulnerability."
nvd
CVE-2024-38145P3HIGHCVSS 7.5fixed in 6.2.9200.25031vr2+1 more2024-08-13
CVE-2024-38145 [HIGH] CWE-476 CVE-2024-38145: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38146P3HIGHCVSS 7.5fixed in 6.2.9200.25031vr2+1 more2024-08-13
CVE-2024-38146 [HIGH] CWE-476 CVE-2024-38146: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38015P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38015 [HIGH] CWE-400 CVE-2024-38015: Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase