cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 61 of 201
CVE-2023-35297P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35297 [HIGH] CWE-843 CVE-2023-35297: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28283P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.242662023-05-09
CVE-2023-28283 [HIGH] CWE-591 CVE-2023-28283: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2017-8484P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8484 [MEDIUM] CVE-2017-8484: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulne
nvd
CVE-2017-8488P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8488 [MEDIUM] CVE-2017-8488: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8478P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8478 [MEDIUM] CVE-2017-8478: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8482P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8482 [MEDIUM] CVE-2017-8482: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8492P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8492 [MEDIUM] CVE-2017-8492: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8462P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8462 [MEDIUM] CVE-2017-8462: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8471P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8471 [MEDIUM] CVE-2017-8471: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulne
nvd
CVE-2017-8485P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8485 [MEDIUM] CVE-2017-8485: The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application. aka "Windows Kernel Information Disclosure Vulnerability," a different vu
nvd
CVE-2017-8473P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8473 [MEDIUM] CVE-2017-8473: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2
nvd
CVE-2016-0037P3HIGHCVSS 7.5vr22016-02-10
CVE-2016-0037 [HIGH] CWE-20 CVE-2016-0037: The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data, aka "Microsoft Active Directory Federation Services Denial of Service Vulnerability."
nvd
CVE-2022-22039P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.237712022-07-12
CVE-2022-22039 [HIGH] CVE-2022-22039: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2017-8470P4MEDIUMCVSS 5.0PoCvr22017-06-15
CVE-2017-8470 [MEDIUM] CWE-200 CVE-2017-8470: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosu
nvd
CVE-2017-8699P3HIGHCVSS 7.0vr22017-09-13
CVE-2017-8699 [HIGH] CWE-20 CVE-2017-8699: Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT Windows Shell in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to run arbitrary code in the context of the current user, due to the way that Windows Shell validates file copy destinations, aka "Windows Shell
nvd
CVE-2017-0166P3HIGHCVSS 8.1vr22017-04-12
CVE-2017-0166 [HIGH] CWE-131 CVE-2017-0166: An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are impro An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."
nvd
CVE-2026-33826P3HIGHCVSS 8.0vr22026-04-14
CVE-2026-33826 [HIGH] CWE-20 CVE-2026-33826: Improper input validation in Windows Active Directory allows an authorized attacker to execute code Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
nvd
CVE-2017-11831P4MEDIUMCVSS 4.7PoCvr22017-11-15
CVE-2017-11831 [MEDIUM] CWE-200 CVE-2017-11831: Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log on to an affected system, and run a specially crafted application that can compromise the user's system due t
nvd
CVE-2026-21236P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.259232026-02-10
CVE-2026-21236 [HIGH] CWE-122 CVE-2026-21236: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21246P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.259232026-02-10
CVE-2026-21246 [HIGH] CWE-122 CVE-2026-21246: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase