cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 152 of 201
CVE-2023-24883P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-24883 [MEDIUM] CWE-126 CVE-2023-24883: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24906P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-24906 [MEDIUM] CWE-190 CVE-2023-24906: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24857P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-24857 [MEDIUM] CWE-126 CVE-2023-24857: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24863P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-24863 [MEDIUM] CWE-190 CVE-2023-24863: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24870P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-24870 [MEDIUM] CWE-126 CVE-2023-24870: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2026-45658P4MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-45658 [MEDIUM] CWE-284 CVE-2026-45658: Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feat Improper access control in Windows BitLocker allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-50298P4MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50298 [MEDIUM] CWE-190 CVE-2026-50298: Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate p Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.
nvd
CVE-2026-50299P4MEDIUMCVSS 6.8vr22026-07-14
CVE-2026-50299 [MEDIUM] CWE-122 CVE-2026-50299: Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to e Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.
nvd
CVE-2026-57097P4MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-57097 [MEDIUM] CWE-426 CVE-2026-57097: Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2026-32170P4MEDIUMCVSS 6.7vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-32170 [MEDIUM] CWE-415 CVE-2026-32170: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21530P4MEDIUMCVSS 6.7vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-21530 [MEDIUM] CWE-415 CVE-2026-21530: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
nvd
CVE-2019-0614P4MEDIUMCVSS 6.5vr22019-04-08
CVE-2019-0614 [MEDIUM] CVE-2019-0614: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0774.
nvd
CVE-2024-26209P4MEDIUMCVSS 5.5vr22024-04-09
CVE-2024-26209 [MEDIUM] CWE-908 CVE-2024-26209: Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
nvd
CVE-2020-0774P4MEDIUMCVSS 6.5vr22020-03-12
CVE-2020-0774 [MEDIUM] CVE-2020-0774: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0874, CVE-2020-0879, CVE-2020-0880, CVE-2020-0882.
nvd
CVE-2019-1286P4MEDIUMCVSS 6.5vr22019-09-11
CVE-2019-1286 [MEDIUM] CVE-2019-1286: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1252.
nvd
CVE-2025-29954P4MEDIUMCVSS 5.9vr2≥ 6.2.9200.0, < 6.2.9200.254752025-05-13
CVE-2025-29954 [MEDIUM] CWE-400 CVE-2025-29954: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-40380P4MEDIUMCVSS 6.2vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-40380 [MEDIUM] CWE-122 CVE-2026-40380: Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execu Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.
nvd
CVE-2019-1466P4MEDIUMCVSS 6.5vr22019-12-10
CVE-2019-1466 [MEDIUM] CVE-2019-1466: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1467.
nvd
CVE-2019-1465P4MEDIUMCVSS 6.5vr22019-12-10
CVE-2019-1465 [MEDIUM] CWE-125 CVE-2019-1465: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1466, CVE-2019-1467.
nvd
CVE-2019-1467P4MEDIUMCVSS 6.5vr22019-12-10
CVE-2019-1467 [MEDIUM] CVE-2019-1467: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1466.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase