Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 191 of 201
CVE-2015-2529P4LOWCVSS 2.1vr22015-09-09
CVE-2015-2529 [LOW] CWE-254 CVE-2015-2529: The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows l
The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."
nvd
CVE-2015-0077P4LOWCVSS 2.1vr22015-03-11
CVE-2015-0077 [LOW] CWE-200 CVE-2015-0077: The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information from kernel memory, and possibly bypa
nvd
CVE-2015-1647P4LOWCVSS 2.1vr22015-04-14
CVE-2015-1647 [LOW] CWE-20 CVE-2015-1647: Virtual Machine Manager (VMM) in Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 allows
Virtual Machine Manager (VMM) in Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 allows guest OS users to cause a denial of service (VMM functionality loss) via a crafted application, aka "Windows Hyper-V DoS Vulnerability."
nvd
CVE-2015-2428P4LOWCVSS 2.1vr22015-08-15
CVE-2015-2428 [LOW] CWE-264 CVE-2015-2428: Object Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi
Object Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels during interaction with object symbolic links that originated in a sandboxed process, which allows local users to gain privi
nvd
CVE-2015-2534P4LOWCVSS 1.9vr22015-09-09
CVE-2015-2534 [LOW] CWE-284 CVE-2015-2534: Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL se
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V Security Feature Bypass Vulnerability."
nvd
CVE-2021-28325MEDIUMCVSS 6.5≥ 6.2.0, < publication2021-04-13
CVE-2021-28325 [MEDIUM] Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
Windows SMB Information Disclosure Vulnerability
cvelistv5
CVE-2021-24086HIGHCVSS 7.5≥ 6.2.0, < publication2021-02-25
CVE-2021-24086 [HIGH] Windows TCP/IP Denial of Service Vulnerability
Windows TCP/IP Denial of Service Vulnerability
Windows TCP/IP Denial of Service Vulnerability
cvelistv5
CVE-2019-1418P4LOWCVSS 3.3vr22019-11-12
CVE-2019-1418 [LOW] CWE-200 CVE-2019-1418: An information vulnerability exists when Windows Modules Installer Service improperly discloses file
An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.
nvd
CVE-2019-1488P4LOWCVSS 3.3vr22019-12-10
CVE-2019-1488 [LOW] CVE-2019-1488: A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific b
A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microsoft Defender Security Feature Bypass Vulnerability'.
nvd
CVE-2022-21977P4LOWCVSS 3.3vr22022-03-09
CVE-2022-21977 [LOW] CVE-2022-21977: Media Foundation Information Disclosure Vulnerability
Media Foundation Information Disclosure Vulnerability
nvd
CVE-2024-38030MEDIUMCVSS 6.5≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38030 [MEDIUM] CWE-200 Windows Themes Spoofing Vulnerability
Windows Themes Spoofing Vulnerability
Windows Themes Spoofing Vulnerability
cvelistv5
CVE-2022-35748HIGHCVSS 7.5≥ 6.2.9200.0, < 6.2.9200.238172023-05-31
CVE-2022-35748 [HIGH] HTTP.sys Denial of Service Vulnerability
HTTP.sys Denial of Service Vulnerability
HTTP.sys Denial of Service Vulnerability
cvelistv5
CVE-2024-26217P4LOWCVSS 3.3vr22024-04-09
CVE-2024-26217 [LOW] CWE-125 CVE-2024-26217: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2021-26414MEDIUMCVSS 4.8≥ 6.2.0, < 6.2.9200.241682021-06-08
CVE-2021-26414 [MEDIUM] Windows DCOM Server Security Feature Bypass
Windows DCOM Server Security Feature Bypass
Windows DCOM Server Security Feature Bypass
cvelistv5
CVE-2022-34689HIGHCVSS 7.5≥ 6.2.9200.0, < 6.2.9200.238172022-10-11
CVE-2022-34689 [HIGH] Windows CryptoAPI Spoofing Vulnerability
Windows CryptoAPI Spoofing Vulnerability
Windows CryptoAPI Spoofing Vulnerability
cvelistv5
CVE-2021-34480MEDIUMCVSS 6.8≥ 6.2.0, < 6.2.9200.23435≥ 6.2.0, < 1.0012021-08-12
CVE-2021-34480 [MEDIUM] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
cvelistv5
CVE-2024-30081HIGHCVSS 7.1≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-30081 [HIGH] CWE-200 Windows NTLM Spoofing Vulnerability
Windows NTLM Spoofing Vulnerability
Windows NTLM Spoofing Vulnerability
cvelistv5
CVE-2025-21377MEDIUMCVSS 6.5≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21377 [MEDIUM] CWE-73 NTLM Hash Disclosure Spoofing Vulnerability
NTLM Hash Disclosure Spoofing Vulnerability
NTLM Hash Disclosure Spoofing Vulnerability
cvelistv5
CVE-2020-17096HIGHCVSS 7.5≥ 6.2.9200.0, < publication2020-12-09
CVE-2020-17096 [HIGH] Windows NTFS Remote Code Execution Vulnerability
Windows NTFS Remote Code Execution Vulnerability
Windows NTFS Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21312P4LOWCVSS 2.4vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21312 [LOW] CWE-908 CVE-2025-21312: Windows Smart Card Reader Information Disclosure Vulnerability
Windows Smart Card Reader Information Disclosure Vulnerability
nvd