Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 179 of 201
CVE-2023-23394P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-23394 [MEDIUM] CWE-822 CVE-2023-23394: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2023-23409P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-23409 [MEDIUM] CWE-20 CVE-2023-23409: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2026-25168P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.259732026-03-10
CVE-2026-25168 [MEDIUM] CWE-476 CVE-2026-25168: Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser
Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2024-20662P4MEDIUMCVSS 4.9vr2≥ 6.2.9200.0, < 6.2.9200.246642024-01-09
CVE-2024-20662 [MEDIUM] CWE-843 CVE-2024-20662: Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
nvd
CVE-2019-0941P4MEDIUMCVSS 4.4vr2≥ 6.2.9200.0, < publication2019-06-12
CVE-2019-0941 [MEDIUM] CWE-19 CVE-2019-0941: A denial of service exists in Microsoft IIS Server when the optional request filtering feature impro
A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use request filtering.
To exploit this vulnerability, an attacker could send a specially crafted req
nvd
CVE-2017-8554P4MEDIUMCVSS 4.7vr22017-06-29
CVE-2017-8554 [MEDIUM] CWE-200 CVE-2017-8554: The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows R
The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticated attacker to obtain memory contents via a specially crafted application.
nvd
CVE-2015-2472P4MEDIUMCVSS 4.3vr22015-08-15
CVE-2015-2472 [MEDIUM] CWE-20 CVE-2015-2472: Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows
Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify certificates, which allows man-in-the-middle attackers to spoof clients via a cra
nvd
CVE-2025-21328P4MEDIUMCVSS 4.3vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21328 [MEDIUM] CWE-41 CVE-2025-21328: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21329P4MEDIUMCVSS 4.3vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21329 [MEDIUM] CWE-41 CVE-2025-21329: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21352P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21352 [MEDIUM] CWE-400 CVE-2025-21352: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2024-38048P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38048 [MEDIUM] CWE-125 CVE-2024-38048: Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
nvd
CVE-2024-38105P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38105 [MEDIUM] CWE-20 CVE-2024-38105: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38101P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38101 [MEDIUM] CWE-125 CVE-2024-38101: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2024-38102P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38102 [MEDIUM] CWE-125 CVE-2024-38102: Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability
nvd
CVE-2022-22010P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.236452022-03-09
CVE-2022-22010 [MEDIUM] CVE-2022-22010: Media Foundation Information Disclosure Vulnerability
Media Foundation Information Disclosure Vulnerability
nvd
CVE-2022-24483P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-24483 [MEDIUM] CVE-2022-24483: Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2015-2535P4MEDIUMCVSS 4.0vr22015-09-09
CVE-2015-2535 [MEDIUM] CWE-17 CVE-2015-2535: Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows
Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service outage) by creating multiple machine accounts, aka "Active Directory Denial of Service Vulnerability."
nvd
CVE-2021-31184P4MEDIUMCVSS 5.5vr2≥ 6.2.0, < 6.2.9200.233472021-05-11
CVE-2021-31184 [MEDIUM] CVE-2021-31184: Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
nvd
CVE-2020-0962P4MEDIUMCVSS 5.5vr22020-04-15
CVE-2020-0962 [MEDIUM] CVE-2020-0962: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0699.
nvd
CVE-2020-0821P4MEDIUMCVSS 5.5vr22020-04-15
CVE-2020-0821 [MEDIUM] CVE-2020-0821: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1007.
nvd