cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 33 of 201
CVE-2019-0719P3CRITICALCVSS 9.1vr22019-11-12
CVE-2019-0719 [CRITICAL] CWE-20 CVE-2019-0719: A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fa A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0721.
nvd
CVE-2026-50508P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-50508 [HIGH] CWE-200 CVE-2026-50508: Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized at Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2019-1102P3HIGHCVSS 8.8vr22019-07-15
CVE-2019-1102 [HIGH] CVE-2019-1102: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2026-33827P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-33827 [HIGH] CWE-362 CVE-2026-33827: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2015-2554P3HIGHCVSS 7.2PoCvr22015-10-14
CVE-2015-2554 [HIGH] CWE-264 CVE-2015-2554: The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability."
nvd
CVE-2015-2511P3MEDIUMCVSS 6.9PoCvr22015-09-09
CVE-2015-2511 [MEDIUM] CWE-119 CVE-2015-2511: The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vuln
nvd
CVE-2015-2518P3MEDIUMCVSS 6.9PoCvr22015-09-09
CVE-2015-2518 [MEDIUM] CVE-2015-2518: The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerabilit
nvd
CVE-2024-26230P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.248212024-04-09
CVE-2024-26230 [HIGH] CWE-416 CVE-2024-26230: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2025-21285P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.252732025-01-14
CVE-2025-21285 [HIGH] CWE-476 CVE-2025-21285: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2015-1644P3HIGHCVSS 7.2PoCvr22015-04-14
CVE-2015-1644 [HIGH] CWE-264 CVE-2015-1644: Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows MS-DOS Device Name Vulnerability."
nvd
CVE-2021-28445P3HIGHCVSS 8.8vr2≥ 6.2.0, < publication2021-04-13
CVE-2021-28445 [HIGH] CVE-2021-28445: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2026-50380P3CRITICALCVSS 9.6vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50380 [CRITICAL] CWE-122 CVE-2026-50380: Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a ne Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21371P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2021-33780P3HIGHCVSS 8.8≥ 6.2.0, < 6.2.9200.234092021-07-14
CVE-2021-33780 [HIGH] CVE-2021-33780: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-23294P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.236452022-03-09
CVE-2022-23294 [HIGH] CVE-2022-23294: Windows Event Tracing Remote Code Execution Vulnerability Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2021-24088P3HIGHCVSS 8.8vr2≥ 6.2.0, < publication2021-02-25
CVE-2021-24088 [HIGH] CVE-2021-24088: Windows Local Spooler Remote Code Execution Vulnerability Windows Local Spooler Remote Code Execution Vulnerability
nvd
CVE-2026-24294P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.259732026-03-10
CVE-2026-24294 [HIGH] CWE-287 CVE-2026-24294: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50177P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-50177 [HIGH] CWE-362 CVE-2025-50177: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-28455P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.233472021-05-11
CVE-2021-28455 [HIGH] CVE-2021-28455: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
nvd
CVE-2021-34525P3HIGHCVSS 8.8vr22021-07-14
CVE-2021-34525 [HIGH] CVE-2021-34525: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase