Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 153 of 201
CVE-2020-0993P4MEDIUMCVSS 6.5vr22020-04-15
CVE-2020-0993 [MEDIUM] CVE-2020-0993: A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, ak
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries, aka 'Windows DNS Denial of Service Vulnerability'.
nvd
CVE-2025-53719P4MEDIUMCVSS 5.7vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-53719 [MEDIUM] CWE-908 CVE-2025-53719: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authoriz
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2025-50156P4MEDIUMCVSS 5.7vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-50156 [MEDIUM] CWE-908 CVE-2025-50156: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authoriz
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
nvd
CVE-2017-0269P4MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0269 [MEDIUM] CWE-20 CVE-2017-0269: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends speci
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
nvd
CVE-2017-0273P4MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0273 [MEDIUM] CVE-2017-0273: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends speci
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.
nvd
CVE-2015-2549P4HIGHCVSS 7.2vr22015-10-14
CVE-2015-2549 [HIGH] CWE-119 CVE-2015-2549: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
nvd
CVE-2026-20927P4MEDIUMCVSS 5.3vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20927 [MEDIUM] CWE-362 CVE-2026-20927: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
nvd
CVE-2014-1814P4HIGHCVSS 7.2vr22014-08-12
CVE-2014-1814 [HIGH] CWE-264 CVE-2014-1814: The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 S
The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that invokes the repair feature for a different application, aka "Windows In
nvd
CVE-2015-2478P4HIGHCVSS 7.2vr22015-11-11
CVE-2015-2478 [HIGH] CWE-264 CVE-2015-2478: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that triggers a Winsock call referencing an invalid address, aka "Winsock Elevation of Privilege Vuln
nvd
CVE-2014-4074P4HIGHCVSS 7.2vr22014-09-10
CVE-2014-4074 [HIGH] CWE-264 CVE-2014-4074: The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows
The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via an application that schedules a crafted task, aka "Task Scheduler Vulnerability."
nvd
CVE-2015-2364P4HIGHCVSS 7.2vr22015-07-14
CVE-2015-2364 [HIGH] CWE-264 CVE-2015-2364: The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that leverages an incorrect bitmap conversion, aka "Graphics Com
nvd
CVE-2014-0300P4HIGHCVSS 7.2vr22014-03-12
CVE-2014-0300 [HIGH] CWE-264 CVE-2014-0300: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege V
nvd
CVE-2015-6126P4HIGHCVSS 7.2vr22015-12-09
CVE-2015-6126 [HIGH] CWE-362 CVE-2015-6126: Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows
Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges or cause a denial of service (use-after-fre
nvd
CVE-2022-22041P4MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.237712022-07-12
CVE-2022-22041 [MEDIUM] CVE-2022-22041: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2024-30019P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30019 [MEDIUM] CWE-400 CVE-2024-30019: DHCP Server Service Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2018-0817P4HIGHCVSS 7.0vr22018-03-14
CVE-2018-0817 [HIGH] CVE-2018-0817: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows
nvd
CVE-2022-22042P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.237712022-07-12
CVE-2022-22042 [MEDIUM] CVE-2022-22042: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2018-0816P4HIGHCVSS 7.0vr22018-03-14
CVE-2018-0816 [HIGH] CVE-2018-0816: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows
nvd
CVE-2017-11853P4MEDIUMCVSS 5.5vr22017-11-15
CVE-2017-11853 [MEDIUM] CVE-2017-11853: Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server
Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing a memory address, aka "Window
nvd
CVE-2018-0868P4HIGHCVSS 7.0vr22018-03-14
CVE-2018-0868 [HIGH] CWE-20 CVE-2018-0868: Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT
Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how input is sanitized, aka "Windows Installer Elevation of Privilege
nvd