Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 66 of 201
CVE-2025-53155P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.256222025-08-12
CVE-2025-53155 [HIGH] CWE-122 CVE-2025-53155: Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges lo
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59242P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.257222025-10-14
CVE-2025-59242 [HIGH] CWE-122 CVE-2025-59242: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-29969P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.254752025-05-13
CVE-2025-29969 [HIGH] CWE-367 CVE-2025-29969: Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attac
Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.
nvd
CVE-2026-40407P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-40407 [HIGH] CWE-122 CVE-2026-40407: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40397P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-40397 [HIGH] CWE-191 CVE-2026-40397: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26160P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-26160 [HIGH] CWE-306 CVE-2026-26160: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an a
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50451P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50451 [HIGH] CWE-306 CVE-2026-50451: Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) all
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58535P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-58535 [HIGH] CWE-908 CVE-2026-58535: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58533P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-58533 [HIGH] CWE-908 CVE-2026-58533: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50497P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50497 [HIGH] CWE-193 CVE-2026-50497: Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose info
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-50445P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50445 [HIGH] CWE-126 CVE-2026-50445: Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a netwo
Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2017-0158P3HIGHCVSS 7.5vr22017-04-12
CVE-2017-0158 [HIGH] CVE-2017-0158: An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2026-0386P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-0386 [HIGH] CWE-284 CVE-2026-0386: Improper access control in Windows Deployment Services allows an unauthorized attacker to execute co
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-60704P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.257682025-11-11
CVE-2025-60704 [HIGH] CWE-325 CVE-2025-60704: Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges
Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2020-1409P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1409 [HIGH] CVE-2020-1409: A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory,
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'.
nvd
CVE-2020-0665P3HIGHCVSS 8.1vr22020-02-11
CVE-2020-0665 [HIGH] CVE-2020-0665: An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default se
An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0734P3HIGHCVSS 8.1vr22019-05-16
CVE-2019-0734 [HIGH] CVE-2019-0734: An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacke
An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege
nvd
CVE-2015-2429P3CRITICALCVSS 9.3vr22015-08-15
CVE-2015-2429 [CRITICAL] CWE-264 CVE-2015-2429: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow attackers to bypass an application sandbox protection mechanism and perform unspecified registry actions via a crafted application, aka "Windows Registry Elevation of Privilege Vul
nvd
CVE-2021-31971P3HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.23372+1 more2021-06-08
CVE-2021-31971 [HIGH] CVE-2021-31971: Windows HTML Platforms Security Feature Bypass Vulnerability
Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2020-1031P3HIGHCVSS 7.5vr2≥ 6.2.0, < publication2020-09-11
CVE-2020-1031 [HIGH] CVE-2020-1031: <p>An information disclosure vulnerability exists in the way that the Windows Server DHCP service im
An information disclosure vulnerability exists in the way that the Windows Server DHCP service improperly discloses the contents of its memory.
To exploit the vulnerability, an unauthenticated attacker could send a specially crafted packet to an affected DHCP server. An attacker who successfully exploited this vulnerability could obtain information to further c
nvd