Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 177 of 201
CVE-2020-0756P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0756 [MEDIUM] CVE-2020-0756: An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service whe
An information disclosure vulnerability exists in the Cryptography Next Generation (CNG) service when it fails to properly handle objects in memory.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the service handles o
nvd
CVE-2020-1160P4MEDIUMCVSS 5.5vr22020-06-09
CVE-2020-1160 [MEDIUM] CVE-2020-1160: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2020-16940P4MEDIUMCVSS 5.5vr2≥ 6.2.0, < publication2020-10-16
CVE-2020-16940 [MEDIUM] CWE-269 CVE-2020-16940: <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) im
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2019-1474P4MEDIUMCVSS 5.5vr22019-12-10
CVE-2019-1474 [MEDIUM] CVE-2019-1474: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1472.
nvd
CVE-2017-8719P4MEDIUMCVSS 4.7vr22017-09-13
CVE-2017-8719 [MEDIUM] CVE-2017-8719: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2017-8709P4MEDIUMCVSS 4.7vr22017-09-13
CVE-2017-8709 [MEDIUM] CVE-2017-8709: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnera
nvd
CVE-2016-7218P4MEDIUMCVSS 4.7vr22016-11-10
CVE-2016-7218 [MEDIUM] CWE-200 CVE-2016-7218: Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2
Bowser.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Windows Bowser.sys Information
nvd
CVE-2020-0658P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0658 [MEDIUM] CVE-2020-0658: An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver w
An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'.
nvd
CVE-2019-1381P4MEDIUMCVSS 5.5vr22019-11-12
CVE-2019-1381 [MEDIUM] CWE-200 CVE-2019-1381: An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unp
An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'Microsoft Windows Information Disclosure Vulnerability'.
nvd
CVE-2020-0871P4MEDIUMCVSS 5.5vr22020-03-12
CVE-2020-0871 [MEDIUM] CVE-2020-0871: An information disclosure vulnerability exists when Windows Network Connections Service fails to pro
An information disclosure vulnerability exists when Windows Network Connections Service fails to properly handle objects in memory, aka 'Windows Network Connections Service Information Disclosure Vulnerability'.
nvd
CVE-2019-1274P4MEDIUMCVSS 5.5vr22019-09-11
CVE-2019-1274 [MEDIUM] CWE-665 CVE-2019-1274: An information disclosure vulnerability exists when the Windows kernel fails to properly initialize
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'.
nvd
CVE-2019-1282P4MEDIUMCVSS 5.5vr22019-09-11
CVE-2019-1282 [MEDIUM] CVE-2019-1282: An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails t
An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'.
nvd
CVE-2017-0169P4MEDIUMCVSS 5.4vr22017-04-12
CVE-2017-0169 [MEDIUM] CVE-2017-0169: An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Window
An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Windows Server 2012. or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0168.
nvd
CVE-2020-0859P4MEDIUMCVSS 5.5vr22020-03-12
CVE-2020-0859 [MEDIUM] CVE-2020-0859: An information vulnerability exists when Windows Modules Installer Service improperly discloses file
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
nvd
CVE-2020-0643P4MEDIUMCVSS 5.5vr22020-01-14
CVE-2020-0643 [MEDIUM] CVE-2020-0643: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerability'.
nvd
CVE-2020-17000P4MEDIUMCVSS 5.5vr2≥ 6.2.0, < publication2020-11-11
CVE-2020-17000 [MEDIUM] CVE-2020-17000: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
nvd
CVE-2020-1116P4MEDIUMCVSS 5.5vr22020-05-21
CVE-2020-1116 [MEDIUM] CVE-2020-1116: An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CS
An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Information Disclosure Vulnerability'.
nvd
CVE-2018-8549P4MEDIUMCVSS 5.5vr22018-11-14
CVE-2018-8549 [MEDIUM] CVE-2018-8549: A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "W
A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2023-28271P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28271 [MEDIUM] CWE-200 CVE-2023-28271: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2020-0941P4MEDIUMCVSS 5.5vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-0941 [MEDIUM] CVE-2020-0941: <p>An information disclosure vulnerability exists when the win32k component improperly provides kern
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, an attacker would have to either log on locally to an affected system, or convince a locally au
nvd