Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 28 of 201
CVE-2021-1722P2CRITICALCVSS 9.8vr2≥ 6.2.0, < publication2021-02-25
CVE-2021-1722 [CRITICAL] CVE-2021-1722: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2017-0211P3MEDIUMCVSS 5.5PoCvr22017-04-12
CVE-2017-0211 [MEDIUM] CWE-610 CVE-2017-0211: An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows S
An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation of Privilege Vulnerability."
nvd
CVE-2015-1722P3HIGHCVSS 7.2PoCvr22015-06-10
CVE-2015-1722 [HIGH] CWE-416 CVE-2015-1722: Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel B
nvd
CVE-2015-1726P3HIGHCVSS 7.2PoCvr22015-06-10
CVE-2015-1726 [HIGH] CWE-416 CVE-2015-1726: Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel B
nvd
CVE-2015-1724P3HIGHCVSS 7.2PoCvr22015-06-10
CVE-2015-1724 [HIGH] CWE-416 CVE-2015-1724: Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel O
nvd
CVE-2019-0790P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0790 [HIGH] CWE-611 CVE-2019-0790: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.
nvd
CVE-2017-8565P3HIGHCVSS 8.1vr22017-07-11
CVE-2017-8565 [HIGH] CVE-2017-8565: Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability when PSObject wraps a CIM Instance, aka "Windows PowerShell Remote Code Execution Vulnerability".
nvd
CVE-2026-56190P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-56190 [CRITICAL] CWE-908 CVE-2026-56190: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2015-2519P3CRITICALCVSS 9.3vr22015-09-09
CVE-2015-2519 [CRITICAL] CWE-190 CVE-2015-2519: Integer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 S
Integer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted .jnt file, aka "Windows Journal Integer Overflow RCE Vulnerability."
nvd
CVE-2016-7217P3HIGHCVSS 8.8vr22016-11-10
CVE-2016-7217 [HIGH] CWE-119 CVE-2016-7217: Media Foundation in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows
Media Foundation in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Media Foundation Memory Corruption Vulnerability."
nvd
CVE-2019-0794P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0794 [HIGH] CVE-2019-0794: A remote code execution vulnerability exists when OLE automation improperly handles objects in memor
A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automation Remote Code Execution Vulnerability'.
nvd
CVE-2019-1212P3CRITICALCVSS 9.8vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-1212 [CRITICAL] CWE-787 CVE-2019-1212: A memory corruption vulnerability exists in the Windows Server DHCP service when processing speciall
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. An attacker who successfully exploited the vulnerability could cause the DHCP server service to stop responding.
To exploit the vulnerability, a remote unauthenticated attacker could send a specially crafted packet to an affected DH
nvd
CVE-2014-0301P3CRITICALCVSS 9.3vr22014-03-12
CVE-2014-0301 [CRITICAL] CWE-415 CVE-2014-0301: Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Se
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via a crafted JPEG image, aka "DirectShow Memory Corrupt
nvd
CVE-2026-42990P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.261322026-07-14
CVE-2026-42990 [CRITICAL] CWE-122 CVE-2026-42990: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50694P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50694 [CRITICAL] CWE-416 CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-0845P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0845 [HIGH] CVE-2019-0845: A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content,
A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCvt Interface Remote Code Execution Vulnerability'.
nvd
CVE-2020-1281P3HIGHCVSS 8.8vr22020-06-09
CVE-2020-1281 [HIGH] CWE-190 CVE-2020-1281: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2016-7224P3MEDIUMCVSS 6.1PoCvr22016-11-10
CVE-2016-7224 [MEDIUM] CWE-284 CVE-2016-7224: Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,
Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."
nvd
CVE-2024-30010P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30010 [HIGH] CWE-23 CVE-2024-30010: Windows Hyper-V Remote Code Execution Vulnerability
Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2016-0070P3MEDIUMCVSS 5.5PoCvr22016-10-14
CVE-2016-0070 [MEDIUM] CWE-200 CVE-2016-0070: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local
nvd