Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 22 of 201
CVE-2025-29962P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.254752025-05-13
CVE-2025-29962 [HIGH] CWE-122 CVE-2025-29962: Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a n
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-1436P2HIGHCVSS 8.8vr22020-07-14
CVE-2020-1436 [HIGH] CWE-787 CVE-2020-1436: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
nvd
CVE-2026-49181P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49181 [CRITICAL] CWE-191 CVE-2026-49181: Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to ele
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2025-33071P2HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.255222025-06-10
CVE-2025-33071 [HIGH] CWE-416 CVE-2025-33071: Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code
Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50439P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50439 [CRITICAL] CWE-416 CVE-2026-50439: Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-43217P2CRITICALCVSS 9.8vr2≥ 6.2.0, < 6.2.9200.23545+1 more2021-12-15
CVE-2021-43217 [CRITICAL] CVE-2021-43217: Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
nvd
CVE-2025-21369P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21369 [HIGH] CWE-122 CVE-2025-21369: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-21368P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21368 [HIGH] CWE-122 CVE-2025-21368: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2016-3373P3MEDIUMCVSS 5.5PoCvr22016-09-14
CVE-2016-3373 [MEDIUM] CWE-264 CVE-2016-3373: The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly implement registry access control, which allows local users to obtain sensitive account information via a crafted application, aka "Windows
nvd
CVE-2015-2527P3HIGHCVSS 7.2PoCvr22015-09-09
CVE-2015-2527 [HIGH] CWE-264 CVE-2015-2527: The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Wind
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulner
nvd
CVE-2017-11779P3HIGHCVSS 8.1vr22017-10-13
CVE-2017-11779 [HIGH] CVE-2017-11779: The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2
The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability".
nvd
CVE-2015-6107P2CRITICALCVSS 9.3vr22015-12-09
CVE-2015-6107 [CRITICAL] CWE-119 CVE-2015-6107: The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10 Gold and 1511, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2010, Lync 2013 SP1, and Live Meeting 2007 Console allows
nvd
CVE-2023-36017P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.245692023-11-14
CVE-2023-36017 [HIGH] CWE-843 CVE-2023-36017: Windows Scripting Engine Memory Corruption Vulnerability
Windows Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2025-21309P2HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21309 [HIGH] CWE-591 CVE-2025-21309: Windows Remote Desktop Services Remote Code Execution Vulnerability
Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
CVE-2026-56194P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-56194 [HIGH] CWE-122 CVE-2026-56194: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2021-36965P2CRITICALCVSS 9.8≥ 6.2.0, < 6.2.9200.234622021-09-15
CVE-2021-36965 [CRITICAL] CVE-2021-36965: Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
nvd
CVE-2017-0060P3MEDIUMCVSS 5.5PoCvr22017-03-17
CVE-2017-0060 [MEDIUM] CWE-200 CVE-2017-0060: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI+ Information Disclosure Vul
nvd
CVE-2016-0195P2HIGHCVSS 8.8vr22016-05-11
CVE-2016-0195 [HIGH] CWE-119 CVE-2016-0195: The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
The Imaging Component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Windows Imaging Component Memory Corruption Vulnerability."
nvd
CVE-2018-1016P2HIGHCVSS 8.8vr22018-04-12
CVE-2018-1016 [HIGH] CVE-2018-1016: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
nvd
CVE-2018-1012P2HIGHCVSS 8.8vr22018-04-12
CVE-2018-1012 [HIGH] CVE-2018-1012: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
nvd