Microsoft Windows Server 2012 vulnerabilities
3,707 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
3,707
CISA KEV
148
actively exploited
Public exploits
290
Exploited in wild
141
Severity breakdown
CRITICAL157HIGH2452MEDIUM1046LOW52
Vulnerabilities
Page 134 of 186
CVE-2019-1434HIGHCVSS 7.8vr22019-11-12
CVE-2019-1434 [HIGH] CVE-2019-1434: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408.
nvd
CVE-2019-1419HIGHCVSS 8.8vr22019-11-12
CVE-2019-1419 [HIGH] CVE-2019-1419: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manage
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1456.
nvd
CVE-2019-1433HIGHCVSS 7.8vr22019-11-12
CVE-2019-1433 [HIGH] CVE-2019-1433: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1435, CVE-2019-1437, CVE-2019-1438.
nvd
CVE-2019-1388HIGHCVSS 7.8KEVvr22019-11-12
CVE-2019-1388 [HIGH] CWE-269 CVE-2019-1388: An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not pr
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1406HIGHCVSS 7.8vr22019-11-12
CVE-2019-1406 [HIGH] CVE-2019-1406: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.
nvd
CVE-2019-1408HIGHCVSS 7.8vr22019-11-12
CVE-2019-1408 [HIGH] CVE-2019-1408: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1434.
nvd
CVE-2019-1415HIGHCVSS 7.8vr22019-11-12
CVE-2019-1415 [HIGH] CVE-2019-1415: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1396HIGHCVSS 7.8vr22019-11-12
CVE-2019-1396 [HIGH] CVE-2019-1396: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1438HIGHCVSS 7.8vr22019-11-12
CVE-2019-1438 [HIGH] CVE-2019-1438: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1407, CVE-2019-1433, CVE-2019-1435, CVE-2019-1437.
nvd
CVE-2019-1389HIGHCVSS 8.4vr22019-11-12
CVE-2019-1389 [HIGH] CWE-20 CVE-2019-1389: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1397, CVE-2019-1398.
nvd
CVE-2019-1405HIGHCVSS 7.8KEVPoCvr22019-11-12
CVE-2019-1405 [HIGH] CWE-269 CVE-2019-1405: An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) servi
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1395HIGHCVSS 7.8vr22019-11-12
CVE-2019-1395 [HIGH] CVE-2019-1395: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1422HIGHCVSS 7.8vr22019-11-12
CVE-2019-1422 [HIGH] CVE-2019-1422: An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creatio
An elevation of privilege vulnerability exists in the way that the iphlpsvc.dll handles file creation allowing for a file overwrite, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1420, CVE-2019-1423.
nvd
CVE-2019-1394HIGHCVSS 7.8vr22019-11-12
CVE-2019-1394 [HIGH] CVE-2019-1394: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1407HIGHCVSS 7.8vr22019-11-12
CVE-2019-1407 [HIGH] CVE-2019-1407: An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handle
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1433, CVE-2019-1435, CVE-2019-1437, CVE-2019-1438.
nvd
CVE-2019-1424HIGHCVSS 8.1vr22019-11-12
CVE-2019-1424 [HIGH] CVE-2019-1424: A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure com
A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
nvd
CVE-2019-1380HIGHCVSS 7.8vr22019-11-12
CVE-2019-1380 [HIGH] CWE-367 CVE-2019-1380: A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka '
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1397HIGHCVSS 8.4vr22019-11-12
CVE-2019-1397 [HIGH] CVE-2019-1397: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1389, CVE-2019-1398.
nvd
CVE-2019-1393HIGHCVSS 7.8vr22019-11-12
CVE-2019-1393 [HIGH] CWE-787 CVE-2019-1393: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1392HIGHCVSS 7.8vr22019-11-12
CVE-2019-1392 [HIGH] CVE-2019-1392: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.
nvd