cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 138 of 201
CVE-2026-33100P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-33100 [HIGH] CWE-416 CVE-2026-33100: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32068P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-32068 [HIGH] CWE-362 CVE-2026-32068: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54107P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-54107 [HIGH] CWE-362 CVE-2026-54107: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50321P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50321 [HIGH] CWE-362 CVE-2026-50321: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34334P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-34334 [HIGH] CWE-362 CVE-2026-34334: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49803P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49803 [HIGH] CWE-362 CVE-2026-49803: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50669P3HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50669 [HIGH] CWE-362 CVE-2026-50669: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24996P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.253682025-03-11
CVE-2025-24996 [MEDIUM] CWE-73 CVE-2025-24996: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2017-8532P3MEDIUMCVSS 6.5vr22017-06-15
CVE-2017-8532 [MEDIUM] CVE-2017-8532: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0286, CVE-2017-0287, CVE-2017-0
nvd
CVE-2026-50426P3MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50426 [MEDIUM] CWE-23 CVE-2026-50426: Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
nvd
CVE-2025-58729P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.257222025-10-14
CVE-2025-58729 [MEDIUM] CWE-1287 CVE-2025-58729: Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an auth Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2023-35351P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35351 [MEDIUM] CWE-416 CVE-2023-35351: Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
nvd
CVE-2023-35346P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35346 [MEDIUM] CWE-591 CVE-2023-35346: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35345P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35345 [MEDIUM] CWE-591 CVE-2023-35345: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35344P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35344 [MEDIUM] CWE-591 CVE-2023-35344: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35310P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35310 [MEDIUM] CWE-591 CVE-2023-35310: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2026-42903P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-42903 [MEDIUM] CWE-476 CVE-2026-42903: Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a ne Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
nvd
CVE-2022-21883P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21883 [HIGH] CVE-2022-21883: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2026-49799P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49799 [MEDIUM] CWE-400 CVE-2026-49799: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
nvd
CVE-2017-8531P3MEDIUMCVSS 6.5vr22017-06-15
CVE-2017-8531 [MEDIUM] CVE-2017-8531: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, Windows Server 2016, Microsoft Office 2007 Service Pack 3, and Microsoft Office 2010 Service Pack 2 allows improper disclosure of memory contents, aka "Graphics Uniscribe Information Disclosure Vulnera
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase