Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 151 of 201
CVE-2018-8333P4HIGHCVSS 7.0vr2v(Server Core installation)2018-10-10
CVE-2018-8333 [HIGH] CWE-404 CVE-2018-8333: An Elevation of Privilege vulnerability exists in Filter Manager when it improperly handles objects
An Elevation of Privilege vulnerability exists in Filter Manager when it improperly handles objects in memory, aka "Microsoft Filter Manager Elevation Of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server
nvd
CVE-2017-8675P4HIGHCVSS 7.0vr22017-09-13
CVE-2017-8675 [HIGH] CWE-119 CVE-2017-8675: The Windows Kernel-Mode Drivers component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7
The Windows Kernel-Mode Drivers component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when the Win32k component fails to properly handle objects in memory, aka "Wi
nvd
CVE-2021-41332P4MEDIUMCVSS 6.5vr2≥ 6.2.0, < 6.2.9200.234902021-10-13
CVE-2021-41332 [MEDIUM] CVE-2021-41332: Windows Print Spooler Information Disclosure Vulnerability
Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2017-0246P4HIGHCVSS 7.0vr22017-05-12
CVE-2017-0246 [HIGH] CVE-2017-0246: The Graphics Component in the kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 S
The Graphics Component in the kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application or in Windows 7 for x64-based Systems and later, cause denial of service, ak
nvd
CVE-2015-6111P4MEDIUMCVSS 6.8vr22015-11-11
CVE-2015-6111 [MEDIUM] CWE-399 CVE-2015-6111: IPSec in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1,
IPSec in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles encryption negotiation, which allows remote authenticated users to cause a denial of service (system hang) via crafted IP traffic, aka "Windows IPSec Denial of Service Vulnerability."
nvd
CVE-2021-38629P4MEDIUMCVSS 6.5≥ 6.2.0, < 6.2.9200.234622021-09-15
CVE-2021-38629 [MEDIUM] CVE-2021-38629: Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
nvd
CVE-2025-21419P4HIGHCVSS 7.1vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21419 [HIGH] CWE-59 CVE-2025-21419: Windows Setup Files Cleanup Elevation of Privilege Vulnerability
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
nvd
CVE-2024-21432P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.247682024-03-12
CVE-2024-21432 [HIGH] CWE-59 CVE-2024-21432: Windows Update Stack Elevation of Privilege Vulnerability
Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2022-21862P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21862 [HIGH] CVE-2022-21862: Windows Application Model Core API Elevation of Privilege Vulnerability
Windows Application Model Core API Elevation of Privilege Vulnerability
nvd
CVE-2022-30151P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30151 [HIGH] CVE-2022-30151: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2024-21439P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.247682024-03-12
CVE-2024-21439 [HIGH] CWE-416 CVE-2024-21439: Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2022-26808P4HIGHCVSS 7.0vr22022-04-15
CVE-2022-26808 [HIGH] CWE-362 CVE-2022-26808: Windows File Explorer Elevation of Privilege Vulnerability
Windows File Explorer Elevation of Privilege Vulnerability
nvd
CVE-2022-26827P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26827 [HIGH] CWE-362 CVE-2022-26827: Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2024-26242P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.248212024-04-09
CVE-2024-26242 [HIGH] CWE-591 CVE-2024-26242: Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2022-34302P4MEDIUMCVSS 6.7vr22022-08-26
CVE-2022-34302 [MEDIUM] CVE-2022-34302: A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this boot
A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Part
nvd
CVE-2023-35361P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35361 [HIGH] CWE-362 CVE-2023-35361: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-35360P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35360 [HIGH] CWE-591 CVE-2023-35360: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2018-0753P4MEDIUMCVSS 5.9vr22018-01-04
CVE-2018-0753 [MEDIUM] CVE-2018-0753: Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wind
Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow a denial of service vulnerability due to the way objects are handled in memory, aka "Windows IPSec Denial of Service Vulnerability".
nvd
CVE-2024-30063P4MEDIUMCVSS 6.7vr2≥ 6.2.9200.0, < 6.2.9200.249192024-06-11
CVE-2024-30063 [MEDIUM] CWE-641 CVE-2024-30063: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2025-49678P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-49678 [HIGH] CWE-362 CVE-2025-49678: Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally
Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd