Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 129 of 201
CVE-2017-0055P3MEDIUMCVSS 6.1vr22017-03-17
CVE-2017-0055 [MEDIUM] CWE-79 CVE-2017-0055: Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Wi
Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, a
nvd
CVE-2025-21331P3HIGHCVSS 7.3vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21331 [HIGH] CWE-59 CVE-2025-21331: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2023-21820P3HIGHCVSS 7.4vr2≥ 6.2.9200.0, < 6.2.9200.241162023-02-14
CVE-2023-21820 [HIGH] CWE-126 CVE-2023-21820: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2023-32021P3HIGHCVSS 7.1vr22023-06-14
CVE-2023-32021 [HIGH] CVE-2023-32021: Windows SMB Witness Service Security Feature Bypass Vulnerability
Windows SMB Witness Service Security Feature Bypass Vulnerability
nvd
CVE-2026-40413P3HIGHCVSS 7.4vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-40413 [HIGH] CWE-476 CVE-2026-40413: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an a
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.
cvelistv5nvd
CVE-2022-26818P3MEDIUMCVSS 6.6vr22022-04-15
CVE-2022-26818 [MEDIUM] CVE-2022-26818: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-27063P3HIGHCVSS 7.5vr2≥ 6.2.0, < publication2021-03-11
CVE-2021-27063 [HIGH] CVE-2021-27063: Windows DNS Server Denial of Service Vulnerability
Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2022-26829P3MEDIUMCVSS 6.6≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26829 [MEDIUM] CWE-362 CVE-2022-26829: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26821P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26821 [MEDIUM] CWE-362 CVE-2022-26821: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26822P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26822 [MEDIUM] CWE-362 CVE-2022-26822: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26819P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26819 [MEDIUM] CWE-362 CVE-2022-26819: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26820P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26820 [MEDIUM] CWE-362 CVE-2022-26820: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26817P3MEDIUMCVSS 6.6vr22022-04-15
CVE-2022-26817 [MEDIUM] CWE-362 CVE-2022-26817: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26814P3MEDIUMCVSS 6.6vr22022-04-15
CVE-2022-26814 [MEDIUM] CWE-362 CVE-2022-26814: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2025-48821P3HIGHCVSS 7.1vr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-48821 [HIGH] CWE-416 CVE-2025-48821: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2022-37959P3MEDIUMCVSS 6.5vr22022-09-13
CVE-2022-37959 [MEDIUM] CVE-2022-37959: Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability
Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability
nvd
CVE-2021-28444P3MEDIUMCVSS 6.5vr22021-04-13
CVE-2021-28444 [MEDIUM] CVE-2021-28444: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2025-27478P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.254232025-04-08
CVE-2025-27478 [HIGH] CWE-122 CVE-2025-27478: Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker t
Heap-based buffer overflow in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-20655P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.246642024-01-09
CVE-2024-20655 [MEDIUM] CWE-416 CVE-2024-20655: Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability
Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability
nvd
CVE-2025-26672P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.254232025-04-08
CVE-2025-26672 [MEDIUM] CWE-126 CVE-2025-26672: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd