cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 21 of 201
CVE-2016-3368P2HIGHCVSS 8.8vr22016-09-14
CVE-2016-3368 [HIGH] CWE-119 CVE-2016-3368: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow remote authenticated users to execute arbitrary code by leveraging a domain account to make a crafted request, aka "Windows Remote Code Execution Vulnerability."
nvd
CVE-2024-38140P2CRITICALCVSS 9.8fixed in 6.2.9200.25031vr2+1 more2024-08-13
CVE-2024-38140 [CRITICAL] CWE-416 CVE-2024-38140: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2023-23415P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-23415 [CRITICAL] CWE-122 CVE-2023-23415: Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
nvd
CVE-2024-43532P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.251182024-10-08
CVE-2024-43532 [HIGH] CWE-636 CVE-2024-43532: Remote Registry Service Elevation of Privilege Vulnerability Remote Registry Service Elevation of Privilege Vulnerability
nvd
CVE-2022-38044P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.239202022-10-11
CVE-2022-38044 [HIGH] CVE-2022-38044: Windows CD-ROM File System Driver Remote Code Execution Vulnerability Windows CD-ROM File System Driver Remote Code Execution Vulnerability
nvd
CVE-2015-0059P3MEDIUMCVSS 6.9PoCvr22015-02-11
CVE-2015-0059 [MEDIUM] CWE-264 CVE-2015-0059: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Window win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote Code Execution Vulnerability."
nvd
CVE-2019-0853P2HIGHCVSS 8.8vr22019-04-09
CVE-2019-0853 [HIGH] CWE-824 CVE-2019-0853: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2014-1818P2CRITICALCVSS 9.3vr22014-06-11
CVE-2014-1818 [CRITICAL] CWE-20 CVE-2014-1818: GDI+ in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wi GDI+ in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP1 and SP2, Live Meeting 2007 Console, Lync 2010 and 2013, Lync 2010 Attendee, and Lync Basic 2013 allows remote attackers to execu
nvd
CVE-2019-0603P3HIGHCVSS 7.5vr22019-04-08
CVE-2019-0603 [HIGH] CVE-2019-0603: A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to
nvd
CVE-2015-6125P2CRITICALCVSS 9.3vr22015-12-09
CVE-2015-6125 [CRITICAL] CVE-2015-6125: Use-after-free vulnerability in the DNS server in Microsoft Windows Server 2008 SP2 and R2 SP1 and S Use-after-free vulnerability in the DNS server in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Use After Free Vulnerability."
nvd
CVE-2015-0092P2CRITICALCVSS 9.3vr22015-03-11
CVE-2015-0092 [CRITICAL] CVE-2015-0092: Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font Driver Remote Code Execution Vulnerability
nvd
CVE-2022-22012P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.237142022-05-10
CVE-2022-22012 [CRITICAL] CVE-2022-22012: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29130P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.237142022-05-10
CVE-2022-29130 [CRITICAL] CVE-2022-29130: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2015-2515P3CRITICALCVSS 9.3vr22015-10-14
CVE-2015-2515 [CRITICAL] CWE-416 CVE-2015-2515: Use-after-free vulnerability in Windows Shell in Microsoft Windows Vista SP2, Windows Server 2008 SP Use-after-free vulnerability in Windows Shell in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted toolbar object, aka "Toolbar Use After Free Vulnerability."
nvd
CVE-2015-2530P2CRITICALCVSS 9.3vr22015-09-09
CVE-2015-2530 [CRITICAL] CVE-2015-2530: Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted .jnt file, aka "Windows Journal RCE Vulnerability," a different vulnerability than CVE-2015-2513 an
nvd
CVE-2023-35349P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.245232023-10-10
CVE-2023-35349 [CRITICAL] CWE-20 CVE-2023-35349: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-20674P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.246642024-01-09
CVE-2024-20674 [HIGH] CWE-305 CVE-2024-20674: Windows Kerberos Security Feature Bypass Vulnerability Windows Kerberos Security Feature Bypass Vulnerability
nvd
CVE-2015-2435P2CRITICALCVSS 9.3vr22015-08-15
CVE-2015-2435 [CRITICAL] CWE-20 CVE-2015-2435: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Silverlight before 5.1.40728 allow remote attacker
nvd
CVE-2017-0118P3MEDIUMCVSS 4.3PoCvr22017-03-17
CVE-2017-0118 [MEDIUM] CVE-2017-0118: Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Uniscribe Information Disclosure Vulnerabili
nvd
CVE-2024-38074P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38074 [CRITICAL] CWE-191 CVE-2024-38074: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase