cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 26 of 201
CVE-2017-0062P3MEDIUMCVSS 4.7PoCvr22017-03-17
CVE-2017-0062 [MEDIUM] CVE-2017-0062: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI+ Information Disclosure Vulnerabili
nvd
CVE-2015-1725P3HIGHCVSS 7.2PoCvr22015-06-10
CVE-2015-1725 [HIGH] CWE-119 CVE-2015-1725: Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Buffer Overflow Vulnerability."
nvd
CVE-2022-34722P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34722 [CRITICAL] CVE-2022-34722: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2020-0964P2HIGHCVSS 8.8vr22020-04-15
CVE-2020-0964 [HIGH] CVE-2020-0964: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2022-35744P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.238172023-05-31
CVE-2022-35744 [CRITICAL] CVE-2022-35744: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2023-36606P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.245232023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2020-0734P2HIGHCVSS 8.8vr22020-02-11
CVE-2020-0734 [HIGH] CVE-2020-0734: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0681.
nvd
CVE-2018-8134P3HIGHCVSS 7.0PoCvr22018-05-09
CVE-2018-8134 [HIGH] CVE-2018-8134: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2018-0751P3HIGHCVSS 7.1PoCvr22018-01-04
CVE-2018-0751 [HIGH] CWE-269 CVE-2018-0751: The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way the Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability". This CVE ID is unique from CV
nvd
CVE-2026-56159P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-56159 [CRITICAL] CWE-122 CVE-2026-56159: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50447P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50447 [CRITICAL] CWE-122 CVE-2026-50447: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58594P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-58594 [CRITICAL] CWE-190 CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-57089P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-57089 [CRITICAL] CWE-416 CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized at Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2014-4118P2CRITICALCVSS 9.3vr22014-11-11
CVE-2014-4118 [CRITICAL] CWE-94 CVE-2014-4118: XML Core Services (aka MSXML) 3.0 in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows S XML Core Services (aka MSXML) 3.0 in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (system-state corruption) via crafted XML cont
nvd
CVE-2018-8225P3HIGHCVSS 8.1vr2v(Server Core installation)2018-06-14
CVE-2018-8225 [HIGH] CVE-2018-8225: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2014-1817P3CRITICALCVSS 9.3vr22014-06-11
CVE-2014-1817 [CRITICAL] CWE-119 CVE-2014-1817: usp10.dll in Uniscribe (aka the Unicode Script Processor) in Microsoft Windows Server 2003 SP2, Wind usp10.dll in Uniscribe (aka the Unicode Script Processor) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP1 and SP2, Live Meeting 2007 Console, Lync 2010 and 2013, Lync 2010 Attendee
nvd
CVE-2024-38104P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38104 [HIGH] CWE-822 CVE-2024-38104: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-38116P2HIGHCVSS 8.8fixed in 6.2.9200.25031vr2+1 more2024-08-13
CVE-2024-38116 [HIGH] CWE-122 CVE-2024-38116: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-43611P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.251182024-10-08
CVE-2024-43611 [HIGH] CWE-20 CVE-2024-43611: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-49080P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.252222024-12-12
CVE-2024-49080 [HIGH] CWE-122 CVE-2024-49080: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase