Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 52 of 201
CVE-2022-35836P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-35836 [HIGH] CVE-2022-35836: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2022-34733P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34733 [HIGH] CVE-2022-34733: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2022-35840P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-35840 [HIGH] CVE-2022-35840: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2021-34497P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.23409+1 more2021-07-14
CVE-2021-34497 [HIGH] CVE-2021-34497: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2021-34447P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.23409+1 more2021-07-16
CVE-2021-34447 [HIGH] CVE-2021-34447: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2024-21369P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.247102024-02-13
CVE-2024-21369 [HIGH] CWE-122 CVE-2024-21369: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21350P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.247102024-02-13
CVE-2024-21350 [HIGH] CWE-190 CVE-2024-21350: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-43519P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.251182024-10-08
CVE-2024-43519 [HIGH] CWE-197 CVE-2024-43519: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-29362P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.243142023-06-14
CVE-2023-29362 [HIGH] CWE-122 CVE-2023-29362: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2026-20843P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20843 [HIGH] CWE-284 CVE-2026-20843: Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized att
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21238P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.259232026-02-10
CVE-2026-21238 [HIGH] CWE-284 CVE-2026-21238: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-26919P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26919 [HIGH] CVE-2022-26919: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2017-8477P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8477 [MEDIUM] CVE-2017-8477: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulne
nvd
CVE-2017-8483P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8483 [MEDIUM] CVE-2017-8483: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2022-30141P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30141 [HIGH] CVE-2022-30141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2017-0300P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-0300 [MEDIUM] CVE-2017-0300: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8490P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8490 [MEDIUM] CVE-2017-8490: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2026-27914P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-27914 [HIGH] CWE-284 CVE-2026-27914: Improper access control in Microsoft Management Console allows an authorized attacker to elevate pri
Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
nvd
CVE-2019-0538P3HIGHCVSS 7.8vr2v(Server Core installation)2019-01-08
CVE-2019-0538 [HIGH] CVE-2019-0538: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2025-24035P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.253682025-03-11
CVE-2025-24035 [HIGH] CWE-591 CVE-2025-24035: Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unau
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
nvd