Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 143 of 201
CVE-2017-0274P3MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0274 [MEDIUM] CVE-2017-0274: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2022-21889P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21889 [HIGH] CVE-2022-21889: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2022-21890P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21890 [HIGH] CVE-2022-21890: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2017-8460P4HIGHCVSS 7.3vr22017-06-15
CVE-2017-8460 [HIGH] CWE-200 CVE-2017-8460: Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511,
Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows information disclosure when a user opens a specially crafted PDF file, aka "Windows PDF Information Disclosure Vulnerability".
nvd
CVE-2023-36707P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.245232023-10-10
CVE-2023-36707 [HIGH] CWE-20 CVE-2023-36707: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2022-35833P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-35833 [HIGH] CVE-2022-35833: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-36585P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.245232023-10-10
CVE-2023-36585 [HIGH] CWE-20 CVE-2023-36585: Windows upnphost.dll Denial of Service Vulnerability
Windows upnphost.dll Denial of Service Vulnerability
nvd
CVE-2023-36395P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.245692023-11-14
CVE-2023-36395 [HIGH] CWE-190 CVE-2023-36395: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2022-34701P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.238172022-08-09
CVE-2022-34701 [HIGH] CWE-400 CVE-2022-34701: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2016-3226P4MEDIUMCVSS 6.5vr22016-06-16
CVE-2016-3226 [MEDIUM] CWE-284 CVE-2016-3226: Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote a
Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory Denial of Service Vulnerability."
nvd
CVE-2020-1256P3MEDIUMCVSS 6.5vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-1256 [MEDIUM] CVE-2020-1256: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2016-3299P4MEDIUMCVSS 5.3vr22016-08-09
CVE-2016-3299 [MEDIUM] CWE-284 CVE-2016-3299: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to hijack network traffic or bypass intended Enhanced Protected Mode (EPM) or application container protection mechanisms, and consequently render untrusted co
nvd
CVE-2020-1097P3MEDIUMCVSS 6.5vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-1097 [MEDIUM] CVE-2020-1097: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2022-33645P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.239202022-10-11
CVE-2022-33645 [HIGH] CVE-2022-33645: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2023-24931P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-24931 [HIGH] CWE-125 CVE-2023-24931: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-21757P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.240752023-01-10
CVE-2023-21757 [HIGH] CWE-476 CVE-2023-21757: Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
nvd
CVE-2022-38041P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.239202022-10-11
CVE-2022-38041 [HIGH] CVE-2022-38041: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2020-1228P3MEDIUMCVSS 6.5vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-1228 [MEDIUM] CVE-2020-1228: <p>A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries.
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.
To exploit the vulnerability, an authenticated attacker could send malicious DNS queries to a target, resulting in a denial of service.
The update addre
nvd
CVE-2023-28241P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28241 [HIGH] CVE-2023-28241: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2020-1091P3MEDIUMCVSS 6.5vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-1091 [MEDIUM] CVE-2020-1091: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd