cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 128 of 201
CVE-2020-1385P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1385 [HIGH] CVE-2020-1385: An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles An elevation of privilege vulnerability exists in the way that the Windows Credential Picker handles objects in memory, aka 'Windows Credential Picker Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1360P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1360 [HIGH] CVE-2020-1360: An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles f An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles file operations, aka 'Windows Profile Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1196P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1196 [HIGH] CVE-2020-1196: An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects i An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects in memory, aka 'Windows Print Configuration Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1302P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1302 [HIGH] CVE-2020-1302: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1272, CVE-2020-1277,
nvd
CVE-2023-24858P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-24858 [HIGH] CWE-126 CVE-2023-24858: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2022-21884P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21884 [HIGH] CVE-2022-21884: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2020-0856P3MEDIUMCVSS 6.5vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-0856 [MEDIUM] CVE-2020-0856: <p>An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mish An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target system. To exploit this condition, an authenticated attacker would need to send a specially crafted reque
nvd
CVE-2017-0298P3HIGHCVSS 7.3vr22017-06-15
CVE-2017-0298 [HIGH] CVE-2017-0298: A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive user, allows an authenticated attacker to run arbitrary code in another user's session, aka "Windows COM
nvd
CVE-2023-36004P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.246142023-12-12
CVE-2023-36004 [HIGH] CWE-287 CVE-2023-36004: Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
nvd
CVE-2017-0073P4MEDIUMCVSS 4.3vr22017-03-17
CVE-2017-0073 [MEDIUM] CVE-2017-0073: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows GDI+ Information Disclosure Vul
nvd
CVE-2021-24103P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-02-25
CVE-2021-24103 [HIGH] CVE-2021-24103: Windows Event Tracing Elevation of Privilege Vulnerability Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2021-43245P3HIGHCVSS 7.8vr2≥ 6.2.0, < 6.2.9200.237712021-12-15
CVE-2021-43245 [HIGH] CVE-2021-43245: Windows Digital TV Tuner Elevation of Privilege Vulnerability Windows Digital TV Tuner Elevation of Privilege Vulnerability
nvd
CVE-2021-43248P3HIGHCVSS 7.8vr2≥ 6.2.0, < 6.2.9200.23545+1 more2021-12-15
CVE-2021-43248 [HIGH] CVE-2021-43248: Windows Digital Media Receiver Elevation of Privilege Vulnerability Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2021-24102P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-02-25
CVE-2021-24102 [HIGH] CWE-269 CVE-2021-24102: Windows Event Tracing Elevation of Privilege Vulnerability Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2022-41095P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.239682022-11-09
CVE-2022-41095 [HIGH] CVE-2022-41095: Windows Digital Media Receiver Elevation of Privilege Vulnerability Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2021-38671P3HIGHCVSS 7.8≥ 6.2.0, < 6.2.9200.234622021-09-15
CVE-2021-38671 [HIGH] CWE-269 CVE-2021-38671: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-38667P3HIGHCVSS 7.8≥ 6.2.0, < 6.2.9200.234622021-09-15
CVE-2021-38667 [HIGH] CWE-269 CVE-2021-38667: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-36927P3HIGHCVSS 7.8vr2≥ 6.2.0, < 6.2.9200.23645+1 more2021-08-12
CVE-2021-36927 [HIGH] CWE-269 CVE-2021-36927: Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability
nvd
CVE-2021-34459P3HIGHCVSS 7.8vr2≥ 6.2.0, < 6.2.9200.234092021-07-16
CVE-2021-34459 [HIGH] CWE-269 CVE-2021-34459: Windows AppContainer Elevation Of Privilege Vulnerability Windows AppContainer Elevation Of Privilege Vulnerability
nvd
CVE-2021-36964P3HIGHCVSS 7.8≥ 6.2.0, < 6.2.9200.234622021-09-15
CVE-2021-36964 [HIGH] CWE-269 CVE-2021-36964: Windows Event Tracing Elevation of Privilege Vulnerability Windows Event Tracing Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase