cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 142 of 201
CVE-2015-0061P4MEDIUMCVSS 4.3vr22015-02-11
CVE-2015-0061 [MEDIUM] CWE-200 CVE-2015-0061: Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process memory via a crafted image file, aka "
nvd
CVE-2025-32715P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.255222025-06-10
CVE-2025-32715 [MEDIUM] CWE-125 CVE-2025-32715: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-32043P3MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-32043 [MEDIUM] CWE-327 CVE-2023-32043: Windows Remote Desktop Security Feature Bypass Vulnerability Windows Remote Desktop Security Feature Bypass Vulnerability
nvd
CVE-2025-55225P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.256752025-09-09
CVE-2025-55225 [MEDIUM] CWE-125 CVE-2025-55225: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-28308P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28308 [MEDIUM] CWE-416 CVE-2023-28308: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28278P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28278 [MEDIUM] CWE-591 CVE-2023-28278: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28305P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28305 [MEDIUM] CWE-416 CVE-2023-28305: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28306P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28306 [MEDIUM] CWE-416 CVE-2023-28306: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28307P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28307 [MEDIUM] CWE-416 CVE-2023-28307: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28255P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28255 [MEDIUM] CWE-591 CVE-2023-28255: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-28256P3MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28256 [MEDIUM] CWE-591 CVE-2023-28256: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2025-54097P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.256752025-09-09
CVE-2025-54097 [MEDIUM] CWE-125 CVE-2025-54097: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54096P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.256752025-09-09
CVE-2025-54096 [MEDIUM] CWE-125 CVE-2025-54096: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54095P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.256752025-09-09
CVE-2025-54095 [MEDIUM] CWE-125 CVE-2025-54095: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2017-8582P4MEDIUMCVSS 5.9vr22017-07-11
CVE-2017-8582 [MEDIUM] CWE-200 CVE-2017-8582: HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when the component improperly handles objects in memory, aka "Https.sys Information Disclosure Vulnerability
nvd
CVE-2013-3876P4HIGHCVSS 7.1vr22013-11-18
CVE-2013-3876 [HIGH] CWE-20 CVE-2013-3876: DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2 DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read
nvd
CVE-2015-0005P4MEDIUMCVSS 4.3vr22015-03-11
CVE-2015-0005 [MEDIUM] CWE-254 CVE-2015-0005: The NETLOGON service in Microsoft Windows Server 2003 SP2, Windows Server 2008 SP2 and R2 SP1, and W The NETLOGON service in Microsoft Windows Server 2003 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2, when a Domain Controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive session information, by running a crafted application and leveraging the abil
nvd
CVE-2026-54126P3MEDIUMCVSS 6.5≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-54126 [MEDIUM] CWE-125 CVE-2026-54126: Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a net Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2019-0821P3MEDIUMCVSS 6.5vr22019-04-09
CVE-2019-0821 [MEDIUM] CVE-2019-0821: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0704.
nvd
CVE-2021-31968P3HIGHCVSS 7.5vr2≥ 6.2.0, < 6.2.9200.233722021-06-08
CVE-2021-31968 [HIGH] CVE-2021-31968: Windows Remote Desktop Services Denial of Service Vulnerability Windows Remote Desktop Services Denial of Service Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase