cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 2 of 201
CVE-2014-4114P1HIGHCVSS 7.8KEVPoCvr22014-10-15
CVE-2014-4114 [HIGH] CVE-2014-4114: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remo
nvd
CVE-2014-6352P1HIGHCVSS 7.8KEVPoCvr22014-10-22
CVE-2014-6352 [HIGH] CVE-2014-6352: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.
nvd
CVE-2018-0824P1HIGHCVSS 8.8KEVPoCvr22018-05-09
CVE-2018-0824 [HIGH] CWE-502 CVE-2018-0824: A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properl A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2019-1458P1HIGHCVSS 7.8KEVPoCRansomwarevr22019-12-10
CVE-2019-1458 [HIGH] CVE-2019-1458: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
nvd
CVE-2014-1812P1HIGHCVSS 8.8KEVPoCRansomwarevr22014-05-14
CVE-2014-1812 [HIGH] CWE-255 CVE-2014-1812: The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging
nvd
CVE-2017-0213P1HIGHCVSS 7.3KEVPoCRansomwarevr22017-05-12
CVE-2017-0213 [HIGH] CVE-2017-0213: Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vul
nvd
CVE-2013-3918P1HIGHCVSS 8.8KEVPoCvr22013-11-12
CVE-2013-3918 [HIGH] CWE-119 CVE-2013-3918: The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial o
nvd
CVE-2021-42278P1HIGHCVSS 7.5KEVPoCRansomwarevr2≥ 6.2.0, < 6.2.9200.235172021-11-10
CVE-2021-42278 [HIGH] CVE-2021-42278: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2016-7255P1HIGHCVSS 7.8KEVPoCRansomwarevr22016-11-10
CVE-2016-7255 [HIGH] CVE-2016-7255: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2018-8453P1HIGHCVSS 7.8KEVPoCRansomwarevr2v(Server Core installation)2018-10-10
CVE-2018-8453 [HIGH] CVE-2018-8453: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2,
nvd
CVE-2018-8120P1HIGHCVSS 7.0KEVPoCRansomwarev(Server Core installation)2018-05-09
CVE-2018-8120 [HIGH] CWE-404 CVE-2018-8120: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
nvd
CVE-2014-4113P1HIGHCVSS 7.8KEVPoCvr22014-10-15
CVE-2014-4113 [HIGH] CVE-2014-4113: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windo win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation
nvd
CVE-2020-1020P1HIGHCVSS 8.8KEVPoCvr22020-04-15
CVE-2020-1020 [HIGH] CVE-2020-1020: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manage A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Cod
nvd
CVE-2015-0016P1HIGHCVSS 7.8KEVPoCvr22015-01-13
CVE-2015-0016 [HIGH] CWE-22 CVE-2015-0016: Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows V Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transiti
nvd
CVE-2016-0151P1HIGHCVSS 7.8KEVPoCRansomwarevr22016-04-12
CVE-2016-0151 [HIGH] CWE-269 CVE-2016-0151: The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
nvd
CVE-2023-28252P1HIGHCVSS 7.8KEVPoCRansomwarevr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28252 [HIGH] CWE-122 CVE-2023-28252: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-0803P1HIGHCVSS 7.8KEVPoCRansomwarevr22019-04-09
CVE-2019-0803 [HIGH] CVE-2019-0803: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.
nvd
CVE-2022-21999P1HIGHCVSS 7.8KEVPoCRansomwarevr2≥ 6.2.9200.0, < 6.2.9200.236052022-02-09
CVE-2022-21999 [HIGH] CWE-22 CVE-2022-21999: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2013-3900P1HIGHCVSS 8.8KEVPoCRansomwarevr2vN/A2013-12-11
CVE-2013-3900 [HIGH] CWE-347 CVE-2013-3900: Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Upd Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, ex
nvd
CVE-2020-1054P1HIGHCVSS 7.8KEVPoCvr22020-05-21
CVE-2020-1054 [HIGH] CWE-787 CVE-2020-1054: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase