cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 30 of 201
CVE-2016-3396P3HIGHCVSS 7.8vr22016-10-14
CVE-2016-3396 [HIGH] CWE-264 CVE-2016-3396: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting
nvd
CVE-2021-34494P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.234092021-07-14
CVE-2021-34494 [HIGH] CVE-2021-34494: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2013-5056P3CRITICALCVSS 9.3vr22013-12-11
CVE-2013-5056 [CRITICAL] CWE-416 CVE-2013-5056: Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a deni
nvd
CVE-2017-0272P3HIGHCVSS 8.1vr22017-05-12
CVE-2017-0272 [HIGH] CVE-2017-0272: The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution
nvd
CVE-2019-1384P3CRITICALCVSS 9.9vr22019-11-12
CVE-2019-1384 [CRITICAL] CWE-522 CVE-2019-1384: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the sessio A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
nvd
CVE-2022-29129P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.237142022-05-10
CVE-2022-29129 [HIGH] CVE-2022-29129: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29128P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.237142022-05-10
CVE-2022-29128 [HIGH] CVE-2022-29128: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29131P3HIGHCVSS 8.8vr22022-05-10
CVE-2022-29131 [HIGH] CVE-2022-29131: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29141P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.237142022-05-10
CVE-2022-29141 [HIGH] CVE-2022-29141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2018-8475P3HIGHCVSS 8.8vr2v(Server Core installation)2018-09-13
CVE-2018-8475 [HIGH] CVE-2018-8475: A remote code execution vulnerability exists when Windows does not properly handle specially crafted A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2020-1299P3HIGHCVSS 8.8vr22020-06-09
CVE-2020-1299 [HIGH] CVE-2020-1299: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2019-0765P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0765 [HIGH] CWE-787 CVE-2019-0765: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.
nvd
CVE-2025-26647P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.254232025-04-08
CVE-2025-26647 [HIGH] CWE-20 CVE-2025-26647: Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges ov Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2020-1435P3HIGHCVSS 8.8vr22020-07-14
CVE-2020-1435 [HIGH] CVE-2020-1435: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2026-42985P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-42985 [HIGH] CWE-416 CVE-2026-42985: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-1060P3HIGHCVSS 8.8vr22019-10-10
CVE-2019-1060 [HIGH] CWE-611 CVE-2019-1060: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2026-49178P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49178 [HIGH] CWE-122 CVE-2026-49178: Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to exec Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
nvd
CVE-2019-0756P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0756 [HIGH] CWE-611 CVE-2019-0756: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2019-1291P3HIGHCVSS 8.8vr22019-09-11
CVE-2019-1291 [HIGH] CVE-2019-1291: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1290.
nvd
CVE-2019-1290P3HIGHCVSS 8.8vr22019-09-11
CVE-2019-1290 [HIGH] CVE-2019-1290: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1291.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase