cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 52 of 201
CVE-2022-35836P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-35836 [HIGH] CVE-2022-35836: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2022-34733P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34733 [HIGH] CVE-2022-34733: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2022-35840P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-35840 [HIGH] CVE-2022-35840: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2021-34497P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.23409+1 more2021-07-14
CVE-2021-34497 [HIGH] CVE-2021-34497: Windows MSHTML Platform Remote Code Execution Vulnerability Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2021-34447P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.23409+1 more2021-07-16
CVE-2021-34447 [HIGH] CVE-2021-34447: Windows MSHTML Platform Remote Code Execution Vulnerability Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2024-21369P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.247102024-02-13
CVE-2024-21369 [HIGH] CWE-122 CVE-2024-21369: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-21350P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.247102024-02-13
CVE-2024-21350 [HIGH] CWE-190 CVE-2024-21350: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-43519P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.251182024-10-08
CVE-2024-43519 [HIGH] CWE-197 CVE-2024-43519: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-29362P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.243142023-06-14
CVE-2023-29362 [HIGH] CWE-122 CVE-2023-29362: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2026-20843P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20843 [HIGH] CWE-284 CVE-2026-20843: Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized att Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21238P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.259232026-02-10
CVE-2026-21238 [HIGH] CWE-284 CVE-2026-21238: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-26919P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26919 [HIGH] CVE-2022-26919: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2017-8477P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8477 [MEDIUM] CVE-2017-8477: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulne
nvd
CVE-2017-8483P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8483 [MEDIUM] CVE-2017-8483: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2022-30141P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30141 [HIGH] CVE-2022-30141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2017-0300P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-0300 [MEDIUM] CVE-2017-0300: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8490P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8490 [MEDIUM] CVE-2017-8490: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2026-27914P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-27914 [HIGH] CWE-284 CVE-2026-27914: Improper access control in Microsoft Management Console allows an authorized attacker to elevate pri Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.
nvd
CVE-2019-0538P3HIGHCVSS 7.8vr2v(Server Core installation)2019-01-08
CVE-2019-0538 [HIGH] CVE-2019-0538: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2025-24035P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.253682025-03-11
CVE-2025-24035 [HIGH] CWE-591 CVE-2025-24035: Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unau Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase