cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 19 of 201
CVE-2019-0943P3HIGHCVSS 7.8PoCvr2≥ 6.2.9200.0, < publication2019-06-12
CVE-2019-0943 [HIGH] CVE-2019-0943: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user
nvd
CVE-2016-3238P2HIGHCVSS 8.1vr22016-07-13
CVE-2016-3238 [HIGH] CWE-254 CVE-2016-3238: The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Window The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows man-in-the-middle attackers to execute arbitrary code by providing a crafted print driver during printer installation, aka "Windows Print Spooler Re
nvd
CVE-2026-50330P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50330 [CRITICAL] CWE-122 CVE-2026-50330: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privi Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-44815P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-44815 [CRITICAL] CWE-121 CVE-2026-44815: Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code o Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2015-0002P3HIGHCVSS 7.2PoCvr22015-01-13
CVE-2015-0002 [HIGH] CWE-264 CVE-2015-0002: The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Micr The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not verify that an impersonation token is associated with an administrative account, which allows local users to gai
nvd
CVE-2015-0057P3HIGHCVSS 7.2PoCvr22015-02-11
CVE-2015-0057 [HIGH] CWE-264 CVE-2015-0057: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windo win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2020-0729P2HIGHCVSS 8.8vr22020-02-11
CVE-2020-0729 [HIGH] CVE-2020-0729: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2020-17051P2CRITICALCVSS 9.8vr2≥ 6.2.0, < publication2020-11-11
CVE-2020-17051 [CRITICAL] CVE-2020-17051: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2025-53143P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-53143 [HIGH] CWE-843 CVE-2025-53143: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2023-28302P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28302 [HIGH] CWE-20 CVE-2023-28302: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-53145P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-53145 [HIGH] CWE-843 CVE-2025-53145: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2025-53144P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-53144 [HIGH] CWE-843 CVE-2025-53144: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2013-3940P2CRITICALCVSS 9.3vr22013-11-13
CVE-2013-3940 [CRITICAL] CWE-190 CVE-2013-3940: Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service
nvd
CVE-2018-8626P2CRITICALCVSS 9.8vr22018-12-12
CVE-2018-8626 [CRITICAL] CWE-787 CVE-2018-8626: A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they f A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2016-0006P3HIGHCVSS 7.3PoCvr22016-01-13
CVE-2016-0006 [HIGH] CWE-264 CVE-2016-0006: The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windo The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation o
nvd
CVE-2019-0555P3HIGHCVSS 7.8PoCvr22019-01-08
CVE-2019-0555 [HIGH] CWE-862 CVE-2019-0555: An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow a An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Window
nvd
CVE-2015-0015P3HIGHCVSS 7.8vr22015-01-13
CVE-2015-0015 [HIGH] CWE-399 CVE-2015-0015: Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow rem Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Network Policy Server (NPS), aka "Network Policy Server RADIUS Implementation Denial of Service Vul
nvd
CVE-2015-0093P2CRITICALCVSS 9.3vr22015-03-11
CVE-2015-0093 [CRITICAL] CVE-2015-0093: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability
nvd
CVE-2016-3227P2CRITICALCVSS 9.8vr22016-06-16
CVE-2016-3227 [CRITICAL] CVE-2016-3227: Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."
nvd
CVE-2019-1343P3MEDIUMCVSS 6.5PoCvr22019-10-10
CVE-2019-1343 [MEDIUM] CVE-2019-1343: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase