Microsoft Windows Server 2012 vulnerabilities

3,707 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
3,707
CISA KEV
149
actively exploited
Public exploits
290
Exploited in wild
141
Severity breakdown
CRITICAL157HIGH2452MEDIUM1046LOW52

Vulnerabilities

Page 140 of 186
CVE-2019-1153MEDIUMCVSS 5.5PoCvr2≥ 6.2.0, < publication2019-08-14
CVE-2019-1153 [MEDIUM] CWE-125 CVE-2019-1153: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2019-1148MEDIUMCVSS 5.5PoCvr2≥ 6.2.0, < publication2019-08-14
CVE-2019-1148 [MEDIUM] CWE-125 CVE-2019-1148: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a spe
nvd
CVE-2019-0785CRITICALCVSS 9.8vr22019-07-15
CVE-2019-0785 [CRITICAL] CWE-787 CVE-2019-0785: A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends s A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
nvd
CVE-2019-0880HIGHCVSS 7.8KEVvr22019-07-15
CVE-2019-0880 [HIGH] CVE-2019-0880: A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka ' A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0811HIGHCVSS 7.5vr22019-07-15
CVE-2019-0811 [HIGH] CWE-19 CVE-2019-0811: A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Windows DNS Server Denial of Service Vulnerability'.
nvd
CVE-2019-1082HIGHCVSS 7.8vr22019-07-15
CVE-2019-1082 [HIGH] CVE-2019-1082: An elevation of privilege vulnerability exists in Microsoft Windows where a certain DLL, with Local An elevation of privilege vulnerability exists in Microsoft Windows where a certain DLL, with Local Service privilege, is vulnerable to race planting a customized DLL.An attacker who successfully exploited this vulnerability could potentially elevate privilege to SYSTEM.The update addresses this vulnerability by requiring SYSTEM privileges for a certain DLL., ak
nvd
CVE-2019-1087HIGHCVSS 7.8vr22019-07-15
CVE-2019-1087 [HIGH] CVE-2019-1087: An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of P An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1086, CVE-2019-1088.
nvd
CVE-2019-1130HIGHCVSS 7.8KEVvr22019-07-15
CVE-2019-1130 [HIGH] CVE-2019-1130: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improp An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.
nvd
CVE-2019-1088HIGHCVSS 7.8vr22019-07-15
CVE-2019-1088 [HIGH] CVE-2019-1088: An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of P An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1086, CVE-2019-1087.
nvd
CVE-2019-1102HIGHCVSS 8.8vr22019-07-15
CVE-2019-1102 [HIGH] CVE-2019-1102: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2019-1085HIGHCVSS 7.8vr22019-07-15
CVE-2019-1085 [HIGH] CVE-2019-1085: An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in me An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows WLAN Service Elevation of Privilege Vulnerability'.
nvd
CVE-2019-1006HIGHCVSS 7.5vr22019-07-15
CVE-2019-1006 [HIGH] CWE-295 CVE-2019-1006: An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
nvd
CVE-2019-1086HIGHCVSS 7.8vr22019-07-15
CVE-2019-1086 [HIGH] CVE-2019-1086: An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of P An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1087, CVE-2019-1088.
nvd
CVE-2019-1089HIGHCVSS 7.8PoCvr22019-07-15
CVE-2019-1089 [HIGH] CVE-2019-1089: An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel i An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an RPC request. To exploit this vulnerability, a low level authenticated attacker could run a specially crafted application. The security update addresses this vulnerability by correcting how rpcss.dll handles these requests., aka 'Windows RPCSS
nvd
CVE-2019-0887HIGHCVSS 8.0vr22019-07-15
CVE-2019-0887 [HIGH] CWE-22 CVE-2019-0887: A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
nvd
CVE-2019-1097MEDIUMCVSS 5.5vr22019-07-15
CVE-2019-1097 [MEDIUM] CVE-2019-1097: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1093.
nvd
CVE-2019-1108MEDIUMCVSS 6.5Exploitedvr22019-07-15
CVE-2019-1108 [MEDIUM] CWE-200 CVE-2019-1108: An information disclosure vulnerability exists when the Windows RDP client improperly discloses the An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote Desktop Protocol Client Information Disclosure Vulnerability'.
nvd
CVE-2019-1094MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1094 [MEDIUM] CWE-200 CVE-2019-1094: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1095, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd
CVE-2019-1126MEDIUMCVSS 5.3vr22019-07-15
CVE-2019-1126 [MEDIUM] CVE-2019-1126: A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which A security feature bypass vulnerability exists in Active Directory Federation Services (ADFS) which could allow an attacker to bypass the extranet lockout policy.To exploit this vulnerability, an attacker could run a specially crafted application, which would allow an attacker to launch a password brute-force attack or cause account lockouts in Active Director
nvd
CVE-2019-1095MEDIUMCVSS 6.5vr22019-07-15
CVE-2019-1095 [MEDIUM] CVE-2019-1095: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1098, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.
nvd