Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 17 of 201
CVE-2023-28293P3HIGHCVSS 7.8PoCvr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28293 [HIGH] CWE-191 CVE-2023-28293: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43639P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.251652024-11-12
CVE-2024-43639 [CRITICAL] CWE-197 CVE-2024-43639: Windows KDC Proxy Remote Code Execution Vulnerability
Windows KDC Proxy Remote Code Execution Vulnerability
nvd
CVE-2017-8589P2CRITICALCVSS 9.8vr22017-07-11
CVE-2017-8589 [CRITICAL] CWE-281 CVE-2017-8589: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability".
nvd
CVE-2017-8683P3MEDIUMCVSS 5.5PoCvr22017-09-13
CVE-2017-8683 [MEDIUM] CVE-2017-8683: Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is
nvd
CVE-2024-38060P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38060 [HIGH] CWE-122 CVE-2024-38060: Windows Imaging Component Remote Code Execution Vulnerability
Windows Imaging Component Remote Code Execution Vulnerability
nvd
CVE-2024-21357P2HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.247102024-02-13
CVE-2024-21357 [HIGH] CWE-843 CVE-2024-21357: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2019-0836P3HIGHCVSS 7.8PoCvr22019-04-09
CVE-2019-0836 [HIGH] CVE-2019-0836: An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV dr
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0841.
nvd
CVE-2018-8410P3HIGHCVSS 7.8PoCv(Server Core installation)2018-09-13
CVE-2018-8410 [HIGH] CWE-404 CVE-2018-8410: An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles regist
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory, aka "Windows Registry Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Server
nvd
CVE-2018-0833P3MEDIUMCVSS 5.3PoCvr22018-02-15
CVE-2018-0833 [MEDIUM] CWE-476 CVE-2018-0833: The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Wi
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability".
nvd
CVE-2018-1010P2HIGHCVSS 8.8vr22018-04-12
CVE-2018-1010 [HIGH] CWE-20 CVE-2018-1010: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2016-0117P3HIGHCVSS 7.8vr22016-03-09
CVE-2016-0117 [HIGH] CWE-20 CVE-2016-0117: The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windo
The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability."
nvd
CVE-2025-53766P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-53766 [CRITICAL] CWE-122 CVE-2025-53766: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
nvd
CVE-2018-0744P3HIGHCVSS 7.0PoCvr22018-01-04
CVE-2018-0744 [HIGH] CVE-2018-0744: The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 160
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability".
nvd
CVE-2025-49730P3HIGHCVSS 7.8PoCvr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-49730 [HIGH] CWE-122 CVE-2025-49730: Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an autho
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49113P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.252222024-12-12
CVE-2024-49113 [HIGH] CWE-125 CVE-2024-49113: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2014-1767P3HIGHCVSS 7.2PoCvr22014-07-08
CVE-2014-1767 [HIGH] CWE-415 CVE-2014-1767: Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drive
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted applica
nvd
CVE-2016-0092P3HIGHCVSS 7.8vr22016-03-09
CVE-2016-0092 [HIGH] CVE-2016-0092: OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Memory Remote Code Execution Vulnerability," a different vulnerability than CVE-2016-0091.
nvd
CVE-2016-0007P3HIGHCVSS 7.8PoCvr22016-01-13
CVE-2016-0007 [HIGH] CVE-2016-0007: The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windo
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation of Privil
nvd
CVE-2021-24078P2CRITICALCVSS 9.8vr2≥ 6.2.0, < publication2021-02-25
CVE-2021-24078 [CRITICAL] CVE-2021-24078: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2019-0731P3HIGHCVSS 7.8PoCvr22019-04-09
CVE-2019-0731 [HIGH] CVE-2019-0731: An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV dr
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836, CVE-2019-0841.
nvd