Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 63 of 201
CVE-2026-44801P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-44801 [HIGH] CWE-416 CVE-2026-44801: Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a netwo
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-42909P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-42909 [HIGH] CWE-362 CVE-2026-42909: Concurrent execution using shared resource with improper synchronization ('race condition') in Remot
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-1410P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1410 [HIGH] CVE-2020-1410: A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vc
A remote code execution vulnerability exists when Windows Address Book (WAB) improperly processes vcard files.To exploit the vulnerability, an attacker could send a malicious vcard that a victim opens using Windows Address Book (WAB), aka 'Windows Address Book Remote Code Execution Vulnerability'.
nvd
CVE-2019-1159P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-1159 [HIGH] CVE-2019-1159: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, a
nvd
CVE-2020-0995P3HIGHCVSS 7.8vr22020-04-15
CVE-2020-0995 [HIGH] CVE-2020-0995: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0889, CVE-2020-0953, CVE-2020-0959, CVE-2020-0960, CVE-2020-0988, CVE-2020-0992, CVE-2020-0994, CVE-2020-0999, CVE-2020-1008.
nvd
CVE-2019-1241P3HIGHCVSS 7.8vr22019-09-11
CVE-2019-1241 [HIGH] CVE-2019-1241: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1242, CVE-2019-1243, CVE-2019-1246, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2020-16933P3HIGHCVSS 8.8vr22020-10-16
CVE-2020-16933 [HIGH] CVE-2020-16933: <p>A security feature bypass vulnerability exists in Microsoft Word software when it fails to proper
A security feature bypass vulnerability exists in Microsoft Word software when it fails to properly handle .LNK files. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with the
nvd
CVE-2020-17162P3HIGHCVSS 8.8vr2≥ 6.2.0, < publication2021-02-25
CVE-2020-17162 [HIGH] CVE-2020-17162: Microsoft Windows Security Feature Bypass Vulnerability
Microsoft Windows Security Feature Bypass Vulnerability
nvd
CVE-2019-0597P3HIGHCVSS 7.8vr22019-03-05
CVE-2019-0597 [HIGH] CVE-2019-0597: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0595, CVE-2019-0596, CVE-2019-0598, CVE-2019-0599, CVE-2019-0625.
nvd
CVE-2019-0625P3HIGHCVSS 7.8vr22019-03-05
CVE-2019-0625 [HIGH] CVE-2019-0625: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0595, CVE-2019-0596, CVE-2019-0597, CVE-2019-0598, CVE-2019-0599.
nvd
CVE-2019-0596P3HIGHCVSS 7.8vr22019-03-05
CVE-2019-0596 [HIGH] CVE-2019-0596: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0595, CVE-2019-0597, CVE-2019-0598, CVE-2019-0599, CVE-2019-0625.
nvd
CVE-2023-21549P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.240752023-01-10
CVE-2023-21549 [HIGH] CWE-285 CVE-2023-21549: Windows SMB Witness Service Elevation of Privilege Vulnerability
Windows SMB Witness Service Elevation of Privilege Vulnerability
nvd
CVE-2025-26669P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.254232025-04-08
CVE-2025-26669 [HIGH] CWE-125 CVE-2025-26669: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-24864P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-24864 [HIGH] CWE-191 CVE-2023-24864: Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-21685P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.241162023-02-14
CVE-2023-21685 [HIGH] CWE-20 CVE-2023-21685: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-21799P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.241162023-02-14
CVE-2023-21799 [HIGH] CWE-122 CVE-2023-21799: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-21686P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.241162023-02-14
CVE-2023-21686 [HIGH] CWE-190 CVE-2023-21686: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2025-30388P3HIGHCVSS 7.8≥ 6.2.9200.0, < 6.2.9200.254752025-05-13
CVE-2025-30388 [HIGH] CWE-122 CVE-2025-30388: Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
nvd
CVE-2022-37989P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.239202022-10-11
CVE-2022-37989 [HIGH] CVE-2022-37989: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2015-2433P4LOWCVSS 2.1PoCvr22015-08-15
CVE-2015-2433 [LOW] CWE-200 CVE-2015-2433: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Kernel ASLR Bypass Vulnerability."
nvd