cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 164 of 201
CVE-2026-20833P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20833 [MEDIUM] CWE-327 CVE-2026-20833: Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker t Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
nvd
CVE-2026-50690P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50690 [MEDIUM] CWE-908 CVE-2026-50690: Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information l Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49180P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49180 [MEDIUM] CWE-59 CVE-2026-49180: Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49801P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49801 [MEDIUM] CWE-908 CVE-2026-49801: Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information l Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
nvd
CVE-2026-49177P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49177 [MEDIUM] CWE-125 CVE-2026-49177: Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
nvd
CVE-2026-54997P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-54997 [MEDIUM] CWE-908 CVE-2026-54997: Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information l Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
nvd
CVE-2026-58614P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-58614 [MEDIUM] CWE-125 CVE-2026-58614: Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature loca Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-58545P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-58545 [MEDIUM] CWE-284 CVE-2026-58545: Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2018-0885P4MEDIUMCVSS 5.8vr22018-03-14
CVE-2018-0885 [MEDIUM] CWE-20 CVE-2018-0885: The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows a denial of service vulnerability due to how input from a privileged user on a guest operating system is validated, a
nvd
CVE-2014-2780P4MEDIUMCVSS 6.9vr22014-07-08
CVE-2014-2780 [MEDIUM] CWE-264 CVE-2014-2780: DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges by leveraging control over a low-integrity process to execute a crafted application, aka "DirectShow Elevation of Privilege Vulnerability."
nvd
CVE-2017-0179P4MEDIUMCVSS 5.8vr22017-04-12
CVE-2017-0179 [MEDIUM] CVE-2017-0179: A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1 A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0182, CVE-2017-01
nvd
CVE-2014-0296P4MEDIUMCVSS 5.1vr22014-06-11
CVE-2014-0296 [MEDIUM] CWE-310 CVE-2014-0296: The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly encrypt sessions, which makes it easier for man-in-the-middle attackers to obtain sensitive information by sniffing the network or modify session content by sending crafted RDP packets, aka "RDP MAC
nvd
CVE-2023-20569P4MEDIUMCVSS 4.7vr22023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the retur A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
nvd
CVE-2020-0689P4MEDIUMCVSS 6.7vr22020-02-11
CVE-2020-0689 [MEDIUM] CVE-2020-0689: A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security F A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'.
nvd
CVE-2017-8688P4MEDIUMCVSS 5.5vr22017-09-13
CVE-2017-8688 [MEDIUM] CVE-2017-8688: Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Se Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique
nvd
CVE-2019-1053P4MEDIUMCVSS 6.3vr2≥ 6.2.9200.0, < publication2019-06-12
CVE-2019-1053 [MEDIUM] CWE-59 CVE-2019-1053: An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder short An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require unprivileged execution on the victim system. The security update addresses the vulnera
nvd
CVE-2022-21928P4MEDIUMCVSS 6.4vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21928 [MEDIUM] CVE-2022-21928: Windows Resilient File System (ReFS) Remote Code Execution Vulnerability Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
nvd
CVE-2021-1683P4MEDIUMCVSS 5.5vr22021-01-12
CVE-2021-1683 [MEDIUM] CVE-2021-1683: Microsoft is aware of the &quot;Impersonation in the Passkey Entry Protocol&quot; vulnerability. For Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2021-1684P4MEDIUMCVSS 5.5vr22021-01-12
CVE-2021-1684 [MEDIUM] CVE-2021-1684: Microsoft is aware of the &quot;Impersonation in the Passkey Entry Protocol&quot; vulnerability. For Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information regarding the vulnerability, please see this statement from the Bluetooth SIG. To address the vulnerability, Microsoft has released a software update that will fail attempts to pair if the remote device exchanges a public key with the same X coordinate
nvd
CVE-2018-8547P4MEDIUMCVSS 5.4vr22018-11-14
CVE-2018-8547 [MEDIUM] CWE-79 CVE-2018-8547: A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Ac A cross-site-scripting (XSS) vulnerability exists when an open source customization for Microsoft Active Directory Federation Services (AD FS) does not properly sanitize a specially crafted web request to an affected AD FS server, aka "Active Directory Federation Services XSS Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows
nvd