cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 187 of 201
CVE-2023-28253P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28253 [MEDIUM] CVE-2023-28253: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2022-41074P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.240182022-12-13
CVE-2022-41074 [MEDIUM] CVE-2022-41074: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2018-8207P4MEDIUMCVSS 4.7vr22018-06-14
CVE-2018-8207 [MEDIUM] CVE-2018-8207: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Server
nvd
CVE-2019-0601P4MEDIUMCVSS 4.7vr22019-03-05
CVE-2019-0601 [MEDIUM] CVE-2019-0601: An information disclosure vulnerability exists when the Human Interface Devices (HID) component impr An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0600.
nvd
CVE-2015-2374P4LOWCVSS 3.3vr22015-07-14
CVE-2015-2374 [LOW] CWE-200 CVE-2015-2374: The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly implement domain-controller communication, which allows remote attackers to discover credentials by leveraging certain PDC access and spoofing the BDC role in a PDC communication channel, aka "Ele
nvd
CVE-2022-21900P4MEDIUMCVSS 4.6vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21900 [MEDIUM] CVE-2022-21900: Windows Hyper-V Security Feature Bypass Vulnerability Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2026-20828P4MEDIUMCVSS 4.6vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20828 [MEDIUM] CWE-125 CVE-2026-20828: Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to d Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-50453P4MEDIUMCVSS 4.6vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50453 [MEDIUM] CWE-125 CVE-2026-50453: Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-49794P4MEDIUMCVSS 4.6vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49794 [MEDIUM] CWE-125 CVE-2026-49794: Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2015-2476P4LOWCVSS 2.6vr22015-08-15
CVE-2015-2476 [LOW] CWE-310 CVE-2015-2476: The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka
nvd
CVE-2022-29121P4MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.237142022-05-10
CVE-2022-29121 [MEDIUM] CVE-2022-29121: Windows WLAN AutoConfig Service Denial of Service Vulnerability Windows WLAN AutoConfig Service Denial of Service Vulnerability
nvd
CVE-2016-3354P4LOWCVSS 3.3vr22016-09-14
CVE-2016-3354 [LOW] CWE-254 CVE-2016-3354: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 S The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability."
nvd
CVE-2019-0754P4MEDIUMCVSS 5.5vr22019-04-09
CVE-2019-0754 [MEDIUM] CVE-2019-0754: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2019-1391P4MEDIUMCVSS 5.5vr22019-11-12
CVE-2019-1391 [MEDIUM] CVE-2019-1391: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2018-12207.
nvd
CVE-2025-21278P4MEDIUMCVSS 5.5vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21278 [MEDIUM] CWE-362 CVE-2025-21278: Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
nvd
CVE-2019-0600P4MEDIUMCVSS 4.7vr22019-03-05
CVE-2019-0600 [MEDIUM] CVE-2019-0600: An information disclosure vulnerability exists when the Human Interface Devices (HID) component impr An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0601.
nvd
CVE-2018-8121P4MEDIUMCVSS 4.7v(Server Core installation)2018-06-14
CVE-2018-8121 [MEDIUM] CWE-665 CVE-2018-8121: An information disclosure vulnerability exists when the Windows kernel improperly initializes object An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207.
nvd
CVE-2025-59198P4MEDIUMCVSS 5.0vr2≥ 6.2.9200.0, < 6.2.9200.257222025-10-14
CVE-2025-59198 [MEDIUM] CWE-20 CVE-2025-59198: Improper input validation in Microsoft Windows Search Component allows an authorized attacker to den Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
nvd
CVE-2016-3258P4MEDIUMCVSS 4.7vr22016-07-13
CVE-2016-3258 [MEDIUM] CWE-264 CVE-2016-3258: Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8 Race condition in the kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Low Integrity protection mechanism and write to files by leveraging unspecified object-manager features, aka "Windows File System Security Feature Bypass."
nvd
CVE-2021-28316P4MEDIUMCVSS 4.6vr2≥ 6.2.0, < publication2021-04-13
CVE-2021-28316 [MEDIUM] CVE-2021-28316: Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase