cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 191 of 201
CVE-2015-2529P4LOWCVSS 2.1vr22015-09-09
CVE-2015-2529 [LOW] CWE-254 CVE-2015-2529: The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows l The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."
nvd
CVE-2015-0077P4LOWCVSS 2.1vr22015-03-11
CVE-2015-0077 [LOW] CWE-200 CVE-2015-0077: The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information from kernel memory, and possibly bypa
nvd
CVE-2015-1647P4LOWCVSS 2.1vr22015-04-14
CVE-2015-1647 [LOW] CWE-20 CVE-2015-1647: Virtual Machine Manager (VMM) in Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 allows Virtual Machine Manager (VMM) in Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 allows guest OS users to cause a denial of service (VMM functionality loss) via a crafted application, aka "Windows Hyper-V DoS Vulnerability."
nvd
CVE-2015-2428P4LOWCVSS 2.1vr22015-08-15
CVE-2015-2428 [LOW] CWE-264 CVE-2015-2428: Object Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi Object Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels during interaction with object symbolic links that originated in a sandboxed process, which allows local users to gain privi
nvd
CVE-2015-2534P4LOWCVSS 1.9vr22015-09-09
CVE-2015-2534 [LOW] CWE-284 CVE-2015-2534: Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL se Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V Security Feature Bypass Vulnerability."
nvd
CVE-2021-28325MEDIUMCVSS 6.5≥ 6.2.0, < publication2021-04-13
CVE-2021-28325 [MEDIUM] Windows SMB Information Disclosure Vulnerability Windows SMB Information Disclosure Vulnerability Windows SMB Information Disclosure Vulnerability
cvelistv5
CVE-2021-24086HIGHCVSS 7.5≥ 6.2.0, < publication2021-02-25
CVE-2021-24086 [HIGH] Windows TCP/IP Denial of Service Vulnerability Windows TCP/IP Denial of Service Vulnerability Windows TCP/IP Denial of Service Vulnerability
cvelistv5
CVE-2019-1418P4LOWCVSS 3.3vr22019-11-12
CVE-2019-1418 [LOW] CWE-200 CVE-2019-1418: An information vulnerability exists when Windows Modules Installer Service improperly discloses file An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
nvd
CVE-2019-1488P4LOWCVSS 3.3vr22019-12-10
CVE-2019-1488 [LOW] CVE-2019-1488: A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific b A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microsoft Defender Security Feature Bypass Vulnerability'.
nvd
CVE-2022-21977P4LOWCVSS 3.3vr22022-03-09
CVE-2022-21977 [LOW] CVE-2022-21977: Media Foundation Information Disclosure Vulnerability Media Foundation Information Disclosure Vulnerability
nvd
CVE-2024-38030MEDIUMCVSS 6.5≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38030 [MEDIUM] CWE-200 Windows Themes Spoofing Vulnerability Windows Themes Spoofing Vulnerability Windows Themes Spoofing Vulnerability
cvelistv5
CVE-2022-35748HIGHCVSS 7.5≥ 6.2.9200.0, < 6.2.9200.238172023-05-31
CVE-2022-35748 [HIGH] HTTP.sys Denial of Service Vulnerability HTTP.sys Denial of Service Vulnerability HTTP.sys Denial of Service Vulnerability
cvelistv5
CVE-2024-26217P4LOWCVSS 3.3vr22024-04-09
CVE-2024-26217 [LOW] CWE-125 CVE-2024-26217: Windows Remote Access Connection Manager Information Disclosure Vulnerability Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2021-26414MEDIUMCVSS 4.8≥ 6.2.0, < 6.2.9200.241682021-06-08
CVE-2021-26414 [MEDIUM] Windows DCOM Server Security Feature Bypass Windows DCOM Server Security Feature Bypass Windows DCOM Server Security Feature Bypass
cvelistv5
CVE-2022-34689HIGHCVSS 7.5≥ 6.2.9200.0, < 6.2.9200.238172022-10-11
CVE-2022-34689 [HIGH] Windows CryptoAPI Spoofing Vulnerability Windows CryptoAPI Spoofing Vulnerability Windows CryptoAPI Spoofing Vulnerability
cvelistv5
CVE-2021-34480MEDIUMCVSS 6.8≥ 6.2.0, < 6.2.9200.23435≥ 6.2.0, < 1.0012021-08-12
CVE-2021-34480 [MEDIUM] Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability
cvelistv5
CVE-2024-30081HIGHCVSS 7.1≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-30081 [HIGH] CWE-200 Windows NTLM Spoofing Vulnerability Windows NTLM Spoofing Vulnerability Windows NTLM Spoofing Vulnerability
cvelistv5
CVE-2025-21377MEDIUMCVSS 6.5≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21377 [MEDIUM] CWE-73 NTLM Hash Disclosure Spoofing Vulnerability NTLM Hash Disclosure Spoofing Vulnerability NTLM Hash Disclosure Spoofing Vulnerability
cvelistv5
CVE-2020-17096HIGHCVSS 7.5≥ 6.2.9200.0, < publication2020-12-09
CVE-2020-17096 [HIGH] Windows NTFS Remote Code Execution Vulnerability Windows NTFS Remote Code Execution Vulnerability Windows NTFS Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21312P4LOWCVSS 2.4vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21312 [LOW] CWE-908 CVE-2025-21312: Windows Smart Card Reader Information Disclosure Vulnerability Windows Smart Card Reader Information Disclosure Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase