cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 150 of 201
CVE-2018-8422P4MEDIUMCVSS 6.5v(Server Core installation)2018-09-13
CVE-2018-8422 [MEDIUM] CWE-200 CVE-2018-8422: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.
nvd
CVE-2020-1179P4MEDIUMCVSS 6.5vr22020-05-21
CVE-2020-1179 [MEDIUM] CVE-2020-1179: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0963, CVE-2020-1141, CVE-2020-1145.
nvd
CVE-2019-0712P4MEDIUMCVSS 6.8vr22019-11-12
CVE-2019-0712 [MEDIUM] CWE-20 CVE-2019-0712: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1309, CVE-2019-1310, CVE-2019-1399.
nvd
CVE-2020-0952P4MEDIUMCVSS 6.5vr22020-04-15
CVE-2020-0952 [MEDIUM] CVE-2020-0952: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2017-0280P4MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0280 [MEDIUM] CVE-2017-0280: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends speci The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.
nvd
CVE-2020-0963P4MEDIUMCVSS 6.5vr22020-05-21
CVE-2020-0963 [MEDIUM] CVE-2020-0963: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1141, CVE-2020-1145, CVE-2020-1179.
nvd
CVE-2026-50324P4MEDIUMCVSS 5.9vr22026-07-14
CVE-2026-50324 [MEDIUM] CWE-835 CVE-2026-50324: Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD F Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2020-1348P4MEDIUMCVSS 6.5vr22020-06-09
CVE-2020-1348 [MEDIUM] CVE-2020-1348: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2020-1468P4MEDIUMCVSS 6.5vr22020-07-14
CVE-2020-1468 [MEDIUM] CVE-2020-1468: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2019-1411P4MEDIUMCVSS 6.5vr22019-11-12
CVE-2019-1411 [MEDIUM] CWE-125 CVE-2019-1411: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1432.
nvd
CVE-2015-1643P4HIGHCVSS 7.2vr22015-04-14
CVE-2015-1643 [HIGH] CWE-264 CVE-2015-1643: Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "NtCreateTransactionManager Type Confusion
nvd
CVE-2018-8444P4MEDIUMCVSS 5.9vr2v(Server Core installation)2018-09-13
CVE-2018-8444 [MEDIUM] CWE-200 CVE-2018-8444: An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2. An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests, aka "Windows SMB Information Disclosure Vulnerability." This affects Windows Server 2012, Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012 R2.
nvd
CVE-2016-3272P4LOWCVSS 2.8vr22016-07-13
CVE-2016-3272 [LOW] CWE-200 CVE-2016-3272: The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles page-fault system calls, which allows local users to obtain sensitive information from an arbitrary process via a crafted application, aka "Windows Kernel Information Disclosure Vulnerability."
nvd
CVE-2014-1819P4HIGHCVSS 7.2vr22014-08-12
CVE-2014-1819 [HIGH] CWE-264 CVE-2014-1819: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windo win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control access to objects associated with font files, which allows local users to gain privileges via a cr
nvd
CVE-2015-0073P4HIGHCVSS 7.2vr22015-03-11
CVE-2015-0073 [HIGH] CWE-264 CVE-2015-0073: The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Se The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain privileges via a crafted application, aka
nvd
CVE-2015-0062P4HIGHCVSS 7.2vr22015-02-11
CVE-2015-0062 [HIGH] CWE-264 CVE-2015-0062: Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gol Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges via a crafted application that leverages incorrect impersonation handling in a process that uses the SeAssignPrimaryTokenPrivilege privilege, aka "Windows Create Process Elevation
nvd
CVE-2019-0718P4MEDIUMCVSS 5.8vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-0718 [MEDIUM] CWE-20 CVE-2019-0718: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0723P4MEDIUMCVSS 5.8vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-0723 [MEDIUM] CWE-20 CVE-2019-0723: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0715P4MEDIUMCVSS 5.8vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-0715 [MEDIUM] CWE-20 CVE-2019-0715: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account
nvd
CVE-2019-0714P4MEDIUMCVSS 5.8vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-0714 [MEDIUM] CWE-20 CVE-2019-0714: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fail A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase