cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 34 of 201
CVE-2020-1412P3HIGHCVSS 8.8vr22020-07-14
CVE-2020-1412 [HIGH] CWE-269 CVE-2020-1412: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2025-21407P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21407 [HIGH] CWE-122 CVE-2025-21407: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21406P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21406 [HIGH] CWE-416 CVE-2025-21406: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21190P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21190 [HIGH] CWE-122 CVE-2025-21190: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21201P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21200P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21200 [HIGH] CWE-122 CVE-2025-21200: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2021-33746P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.234092021-07-14
CVE-2021-33746 [HIGH] CVE-2021-33746: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35322P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35322 [HIGH] CWE-121 CVE-2023-35322: Windows Deployment Services Remote Code Execution Vulnerability Windows Deployment Services Remote Code Execution Vulnerability
nvd
CVE-2025-54106P3HIGHCVSS 8.8vr22025-09-09
CVE-2025-54106 [HIGH] CWE-190 CVE-2025-54106: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unautho Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-0772P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0772 [HIGH] CVE-2019-0772: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0667.
nvd
CVE-2023-21695P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.241162023-02-14
CVE-2023-21695 [HIGH] CWE-122 CVE-2023-21695: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
nvd
CVE-2025-33066P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.255222025-06-10
CVE-2025-33066 [HIGH] CWE-122 CVE-2025-33066: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49657P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-49657 [HIGH] CWE-122 CVE-2025-49657: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-48824P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-48824 [HIGH] CWE-122 CVE-2025-48824: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-47998P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-47998 [HIGH] CWE-122 CVE-2025-47998: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49676P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-49676 [HIGH] CWE-122 CVE-2025-49676: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49672P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-49672 [HIGH] CWE-122 CVE-2025-49672: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-32157P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-32157 [HIGH] CWE-416 CVE-2026-32157: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50500P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50500 [HIGH] CWE-416 CVE-2026-50500: Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a networ Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50474P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50474 [HIGH] CWE-416 CVE-2026-50474: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase