cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 161 of 201
CVE-2016-0190P4MEDIUMCVSS 5.5vr22016-05-11
CVE-2016-0190 [MEDIUM] CWE-200 CVE-2016-0190: Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB disk accesses originate from the user who mounted a disk, which allows local users to read arbitrary files on these disks via RemoteFX requests, aka "Remote Desktop Protocol Drive Redirection Information D
nvd
CVE-2025-59258P4MEDIUMCVSS 6.2vr2≥ 6.2.9200.0, < 6.2.9200.257222025-10-14
CVE-2025-59258 [MEDIUM] CWE-532 CVE-2025-59258: Insertion of sensitive information into log file in Active Directory Federation Services allows an u Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.
nvd
CVE-2019-1470P4MEDIUMCVSS 6.0vr22019-12-10
CVE-2019-1470 [MEDIUM] CWE-20 CVE-2019-1470: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
nvd
CVE-2022-30154P4MEDIUMCVSS 5.3vr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30154 [MEDIUM] CVE-2022-30154: Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability
nvd
CVE-2026-50475P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50475 [MEDIUM] CWE-126 CVE-2026-50475: Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally. Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
nvd
CVE-2026-20839P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20839 [MEDIUM] CWE-284 CVE-2026-20839: Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker t Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.
nvd
CVE-2015-0080P4MEDIUMCVSS 4.3vr22015-03-11
CVE-2015-0080 [MEDIUM] CWE-200 CVE-2015-0080: Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG images, which allows remote attackers to obtain sensitive information from process memory via a cra
nvd
CVE-2026-50341P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50341 [MEDIUM] CWE-126 CVE-2026-50341: Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2026-42914P4MEDIUMCVSS 5.3vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-42914 [MEDIUM] CWE-125 CVE-2026-42914: Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.
cvelistv5nvd
CVE-2017-0191P4MEDIUMCVSS 5.8vr22017-04-12
CVE-2017-0191 [MEDIUM] CVE-2017-0191: A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows A denial of service vulnerability exists in the way that Windows 7, Windows 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding, aka "Windows Denial of Service Vulnerabilit
nvd
CVE-2017-0186P4MEDIUMCVSS 5.8vr22017-04-12
CVE-2017-0186 [MEDIUM] CVE-2017-0186: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-20
nvd
CVE-2024-30037P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30037 [MEDIUM] CWE-125 CVE-2024-30037: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2017-0182P4MEDIUMCVSS 5.8vr22017-04-12
CVE-2017-0182 [MEDIUM] CVE-2017-0182: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE
nvd
CVE-2019-0716P4MEDIUMCVSS 5.8vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-0716 [MEDIUM] CVE-2019-0716: A denial of service vulnerability exists when Windows improperly handles objects in memory. An attac A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an
nvd
CVE-2017-0183P4MEDIUMCVSS 5.8vr22017-04-12
CVE-2017-0183 [MEDIUM] CVE-2017-0183: A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE
nvd
CVE-2021-33745P4MEDIUMCVSS 6.5vr2≥ 6.2.0, < 6.2.9200.234092021-07-14
CVE-2021-33745 [MEDIUM] CVE-2021-33745: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2021-34499P4MEDIUMCVSS 6.5vr2≥ 6.2.0, < 6.2.9200.234092021-07-14
CVE-2021-34499 [MEDIUM] CVE-2021-34499: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2017-0171P4MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0171 [MEDIUM] CWE-20 CVE-2017-0171: Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 a Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 are configured to answer version queries, aka "Windows DNS Server Denial of Service Vulnerability".
nvd
CVE-2021-40463P4MEDIUMCVSS 6.5≥ 6.2.0, < 6.2.9200.234902021-10-13
CVE-2021-40463 [MEDIUM] CVE-2021-40463: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2020-0730P4HIGHCVSS 7.1vr22020-02-11
CVE-2020-0730 [HIGH] CWE-59 CVE-2020-0730: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) impro An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase