Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 5 of 201
CVE-2017-8543P1CRITICALCVSS 9.8KEVvr22017-06-15
CVE-2017-8543 [CRITICAL] CWE-281 CVE-2017-8543: Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1,
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to take control of the affected system when Windows Search fai
nvd
CVE-2016-7256P1HIGHCVSS 8.8KEVvr22016-11-10
CVE-2016-7256 [HIGH] CVE-2016-7256: atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2
atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Open Type Font Remote Code Execution Vulnera
nvd
CVE-2026-20805P2MEDIUMCVSS 5.5KEVPoCvr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20805 [MEDIUM] CWE-200 CVE-2026-20805: Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an auth
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2021-33742P1HIGHCVSS 8.8KEVvr2≥ 6.2.0, < 6.2.9200.23372+1 more2021-06-08
CVE-2021-33742 [HIGH] CWE-787 CVE-2021-33742: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2014-4148P1HIGHCVSS 8.8KEVvr22014-10-15
CVE-2014-4148 [HIGH] CWE-94 CVE-2014-4148: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windo
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka
nvd
CVE-2016-3393P1HIGHCVSS 7.8KEVvr22016-10-14
CVE-2016-3393 [HIGH] CVE-2016-3393: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component RCE Vulnerability."
nvd
CVE-2024-43572P1HIGHCVSS 7.8KEVvr2≥ 6.2.9200.0, < 6.2.9200.251182024-10-08
CVE-2024-43572 [HIGH] CWE-707 CVE-2024-43572: Microsoft Management Console Remote Code Execution Vulnerability
Microsoft Management Console Remote Code Execution Vulnerability
nvd
CVE-2020-0938P1HIGHCVSS 7.8KEVvr22020-04-15
CVE-2020-0938 [HIGH] CWE-787 CVE-2020-0938: A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manage
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Re
nvd
CVE-2022-34713P1HIGHCVSS 7.8KEVvr2≥ 6.2.9200.0, < 6.2.9200.238172022-08-09
CVE-2022-34713 [HIGH] CVE-2022-34713: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
nvd
CVE-2026-21510P1HIGHCVSS 8.8KEVvr2≥ 6.2.9200.0, < 6.2.9200.259232026-02-10
CVE-2026-21510 [HIGH] CWE-693 CVE-2026-21510: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-41128P1HIGHCVSS 8.8KEVvr2≥ 6.2.9200.0, < 6.2.9200.239682022-11-09
CVE-2022-41128 [HIGH] CWE-787 CVE-2022-41128: Windows Scripting Languages Remote Code Execution Vulnerability
Windows Scripting Languages Remote Code Execution Vulnerability
nvd
CVE-2026-21513P1HIGHCVSS 8.8KEVvr2≥ 6.2.9200.0, < 6.2.9200.259232026-02-10
CVE-2026-21513 [HIGH] CWE-693 CVE-2026-21513: Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a securit
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-36036P1HIGHCVSS 7.8KEVRansomwarevr2≥ 6.2.9200.0, < 6.2.9200.245692023-11-14
CVE-2023-36036 [HIGH] CWE-122 CVE-2023-36036: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-23376P1HIGHCVSS 7.8KEVRansomwarevr2≥ 6.2.9200.0, < 6.2.9200.241162023-02-14
CVE-2023-23376 [HIGH] CWE-122 CVE-2023-23376: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-0986P1HIGHCVSS 7.8KEVRansomwarevr22020-06-09
CVE-2020-0986 [HIGH] CWE-787 CVE-2020-0986: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-
nvd
CVE-2019-0903P1HIGHCVSS 8.8KEVvr22019-05-16
CVE-2019-0903 [HIGH] CVE-2019-0903: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2024-26169P1HIGHCVSS 7.8KEVRansomwarevr22024-03-12
CVE-2024-26169 [HIGH] CWE-269 CVE-2024-26169: Windows Error Reporting Service Elevation of Privilege Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability
nvd
CVE-2020-1040P1CRITICALCVSS 9.0KEVvr22020-07-14
CVE-2020-1040 [CRITICAL] CVE-2020-1040: A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to pr
A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1032, CVE-2020-1036, CVE-2020-1041, CVE-2020-1042, CVE-2020-1043.
nvd
CVE-2022-41073P1HIGHCVSS 7.8KEVRansomwarevr2≥ 6.2.9200.0, < 6.2.9200.239682022-11-09
CVE-2022-41073 [HIGH] CWE-787 CVE-2022-41073: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2026-56155P1HIGHCVSS 7.8KEVvr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-56155 [HIGH] CWE-1220 CVE-2026-56155: Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
nvd