cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 51 of 201
CVE-2026-20848P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20848 [HIGH] CWE-362 CVE-2026-20848: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2020-1339P3HIGHCVSS 8.8vr2≥ 6.2.0, < publication2020-08-17
CVE-2020-1339 [HIGH] CVE-2020-1339: A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objec A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2026-50685P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50685 [HIGH] CWE-415 CVE-2026-50685: Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-58531P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-58531 [HIGH] CWE-362 CVE-2026-58531: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2021-42291P3HIGHCVSS 8.8≥ 6.2.0, < 6.2.9200.235172021-11-10
CVE-2021-42291 [HIGH] CWE-269 CVE-2021-42291: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2021-42282P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.235172021-11-10
CVE-2021-42282 [HIGH] CWE-269 CVE-2021-42282: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2020-1508P3HIGHCVSS 8.8vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-1508 [HIGH] CVE-2020-1508: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2026-58608P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-58608 [HIGH] CWE-362 CVE-2026-58608: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
nvd
CVE-2017-0294P3HIGHCVSS 7.8vr22017-06-15
CVE-2017-0294 [HIGH] CVE-2017-0294: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute remote code when Windows fails to properly handle cabinet files, aka "Windows Remote Code Execution Vulnerability".
nvd
CVE-2022-21851P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21851 [HIGH] CVE-2022-21851: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-21850P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21850 [HIGH] CVE-2022-21850: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-34734P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34734 [HIGH] CVE-2022-34734: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34727P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34727 [HIGH] CVE-2022-34727: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34732P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34732 [HIGH] CVE-2022-34732: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34730P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34730 [HIGH] CVE-2022-34730: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2022-34726P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34726 [HIGH] CVE-2022-34726: Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd
CVE-2024-38054P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38054 [HIGH] CWE-122 CVE-2024-38054: Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-34731P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34731 [HIGH] CVE-2022-34731: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2022-35834P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-35834 [HIGH] CVE-2022-35834: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2022-35835P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-35835 [HIGH] CVE-2022-35835: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase