Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 160 of 201
CVE-2022-35837P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-35837 [MEDIUM] CVE-2022-35837: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-34690P4HIGHCVSS 7.1vr2≥ 6.2.9200.0, < 6.2.9200.238172022-08-09
CVE-2022-34690 [HIGH] CVE-2022-34690: Windows Fax Service Elevation of Privilege Vulnerability
Windows Fax Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21760P4HIGHCVSS 7.1vr2≥ 6.2.9200.0, < 6.2.9200.240752023-01-10
CVE-2023-21760 [HIGH] CWE-59 CVE-2023-21760: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2023-29369P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.243142023-06-14
CVE-2023-29369 [MEDIUM] CWE-190 CVE-2023-29369: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2022-38006P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-38006 [MEDIUM] CVE-2022-38006: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2018-0976P4MEDIUMCVSS 5.3vr2v(Server Core installation)2018-04-12
CVE-2018-0976 [MEDIUM] CVE-2018-0976: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.
nvd
CVE-2022-37977P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.239202022-10-11
CVE-2022-37977 [MEDIUM] CVE-2022-37977: Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
nvd
CVE-2023-35318P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35318 [MEDIUM] CWE-125 CVE-2023-35318: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-35319P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35319 [MEDIUM] CWE-125 CVE-2023-35319: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-35314P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35314 [MEDIUM] CWE-125 CVE-2023-35314: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33164P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-33164 [MEDIUM] CWE-125 CVE-2023-33164: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2025-50158P4HIGHCVSS 7.0vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-50158 [HIGH] CWE-367 CVE-2025-50158: Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to
Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2021-33764P4MEDIUMCVSS 5.9≥ 6.2.0, < 6.2.9200.234092021-07-14
CVE-2021-33764 [MEDIUM] CVE-2021-33764: Windows Key Distribution Center Information Disclosure Vulnerability
Windows Key Distribution Center Information Disclosure Vulnerability
nvd
CVE-2023-21560P4MEDIUMCVSS 6.6vr2≥ 6.2.9200.0, < 6.2.9200.240752023-01-10
CVE-2023-21560 [MEDIUM] CWE-122 CVE-2023-21560: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28269P4MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28269 [MEDIUM] CWE-122 CVE-2023-28269: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28249P4MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28249 [MEDIUM] CWE-863 CVE-2023-28249: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2024-38013P4MEDIUMCVSS 6.7vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38013 [MEDIUM] CWE-59 CVE-2024-38013: Microsoft Windows Server Backup Elevation of Privilege Vulnerability
Microsoft Windows Server Backup Elevation of Privilege Vulnerability
nvd
CVE-2026-45608P4MEDIUMCVSS 6.8vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-45608 [MEDIUM] CWE-125 CVE-2026-45608: Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information lo
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
nvd
CVE-2022-35754P4MEDIUMCVSS 6.7vr2≥ 6.2.9200.0, < 6.2.9200.238172023-05-31
CVE-2022-35754 [MEDIUM] CVE-2022-35754: Unified Write Filter Elevation of Privilege Vulnerability
Unified Write Filter Elevation of Privilege Vulnerability
nvd
CVE-2022-22028P4MEDIUMCVSS 5.9vr2≥ 6.2.9200.0, < 6.2.9200.237712022-07-12
CVE-2022-22028 [MEDIUM] CVE-2022-22028: Windows Network File System Information Disclosure Vulnerability
Windows Network File System Information Disclosure Vulnerability
nvd