cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 31 of 201
CVE-2019-0736P3CRITICALCVSS 9.8vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-0736 [CRITICAL] CWE-787 CVE-2019-0736: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vulnerability, an attacker could send specially crafted DHCP responses to a client. The securi
nvd
CVE-2021-36958P3HIGHCVSS 7.8≥ 6.2.0, < 6.2.9200.234622021-08-12
CVE-2021-36958 [HIGH] CVE-2021-36958: <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly pe A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
nvd
CVE-2024-30078P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.249192024-06-11
CVE-2024-30078 [HIGH] CWE-20 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability Windows Wi-Fi Driver Remote Code Execution Vulnerability
nvd
CVE-2025-33070P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.255222025-06-10
CVE-2025-33070 [HIGH] CWE-908 CVE-2025-33070: Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privile Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2015-2507P3HIGHCVSS 7.2PoCvr22015-09-09
CVE-2015-2507 [HIGH] CWE-264 CVE-2015-2507: The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, W The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of Privilege Vulnerability," a different vulnerabili
nvd
CVE-2015-2528P3HIGHCVSS 7.2PoCvr22015-09-09
CVE-2015-2528 [HIGH] CVE-2015-2528: Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Wind Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2524.
nvd
CVE-2015-2524P3HIGHCVSS 7.2PoCvr22015-09-09
CVE-2015-2524 [HIGH] CWE-264 CVE-2015-2524: Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Wind Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2528.
nvd
CVE-2015-2365P3HIGHCVSS 7.2PoCvr22015-07-14
CVE-2015-2365 [HIGH] CWE-264 CVE-2015-2365: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability
nvd
CVE-2015-2366P3HIGHCVSS 7.2PoCvr22015-07-14
CVE-2015-2366 [HIGH] CWE-264 CVE-2015-2366: win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Window win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2015-1721P3HIGHCVSS 7.2PoCvr22015-06-10
CVE-2015-1721 [HIGH] CWE-476 CVE-2015-1721: The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted appl
nvd
CVE-2015-2553P3HIGHCVSS 7.2PoCvr22015-10-14
CVE-2015-2553 [HIGH] CWE-264 CVE-2015-2553: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes it easier for local users to gain privileges by leveraging certain sandbox access, aka "Windows Mount P
nvd
CVE-2019-1439P3MEDIUMCVSS 6.5vr22019-11-12
CVE-2019-1439 [MEDIUM] CWE-200 CVE-2019-1439: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.
nvd
CVE-2024-38240P3CRITICALCVSS 9.8vr22024-09-10
CVE-2024-38240 [CRITICAL] CWE-125 CVE-2024-38240: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2015-0058P3HIGHCVSS 7.2PoCvr22015-02-11
CVE-2015-0058 [HIGH] CWE-415 CVE-2015-0058: Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free Vulnerability."
nvd
CVE-2016-0075P3MEDIUMCVSS 5.5PoCvr22016-10-14
CVE-2016-0075 [MEDIUM] CVE-2016-0075: The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability," a different vulnerability than CVE-201
nvd
CVE-2026-49798P3CRITICALCVSS 9.3vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49798 [CRITICAL] CWE-416 CVE-2026-49798: Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2020-1067P3HIGHCVSS 8.8vr22020-05-21
CVE-2020-1067 [HIGH] CVE-2020-1067: A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
nvd
CVE-2019-0662P3HIGHCVSS 8.8vr22019-03-05
CVE-2019-0662 [HIGH] CVE-2019-0662: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0618.
nvd
CVE-2025-26645P3HIGHCVSS 8.8≥ 6.2.9200.0, < 6.2.9200.253682025-03-11
CVE-2025-26645 [HIGH] CWE-23 CVE-2025-26645: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-49164P3CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-49164 [CRITICAL] CWE-122 CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to ex Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase