cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 71 of 201
CVE-2025-55231P3HIGHCVSS 7.5vr22025-08-21
CVE-2025-55231 [HIGH] CWE-362 CVE-2025-55231: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-44799P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.261322026-06-09
CVE-2026-44799 [HIGH] CWE-122 CVE-2026-44799: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-1153P3HIGHCVSS 7.8vr22020-05-21
CVE-2020-1153 [HIGH] CVE-2020-1153: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2020-0907P3HIGHCVSS 7.8vr22020-04-15
CVE-2020-0907 [HIGH] CVE-2020-0907: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2026-32161P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-32161 [HIGH] CWE-362 CVE-2026-32161: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2022-35756P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.238172023-05-31
CVE-2022-35756 [HIGH] CVE-2022-35756: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2015-2430P3CRITICALCVSS 9.3vr22015-08-15
CVE-2015-2430 [CRITICAL] CWE-264 CVE-2015-2430: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow attackers to bypass an application sandbox protection mechanism and perform unspecified filesystem actions via a crafted application, aka "Windows Filesystem Elevation of Privilege
nvd
CVE-2016-3319P3HIGHCVSS 7.0vr22016-08-09
CVE-2016-3319 [HIGH] CWE-284 CVE-2016-3319: The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allows remote attackers to execute arbitrary code via a crafted PDF file, aka "Microsoft PDF Remote Code Execution Vulnerability."
nvd
CVE-2024-30025P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30025 [HIGH] CWE-125 CVE-2024-30025: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2015-0079P3HIGHCVSS 7.8vr22015-03-11
CVE-2015-0079 [HIGH] CWE-399 CVE-2015-0079: The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to cause a denial of service (memory consumption and RDP outage) by establishing many RDP sessions that do not properly free allocated memory, aka "Remote Desktop Protocol (RDP) Denial of Servic
nvd
CVE-2019-0879P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0879 [HIGH] CVE-2019-0879: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0877.
nvd
CVE-2018-0959P3HIGHCVSS 7.6vr2v(Server Core installation)2018-05-09
CVE-2018-0959 [HIGH] CWE-20 CVE-2018-0959: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2023-28244P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28244 [HIGH] CWE-327 CVE-2023-28244: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-37966P3HIGHCVSS 8.1vr2vN/A2022-11-09
CVE-2022-37966 [HIGH] CVE-2022-37966: Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
nvd
CVE-2019-1484P3HIGHCVSS 7.8vr22019-12-10
CVE-2019-1484 [HIGH] CWE-20 CVE-2019-1484: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2025-49687P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.255732025-07-08
CVE-2025-49687 [HIGH] CWE-125 CVE-2025-49687: Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate p Out-of-bounds read in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-0738P3HIGHCVSS 8.8vr22020-02-11
CVE-2020-0738 [HIGH] CWE-787 CVE-2020-0738: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
nvd
CVE-2023-29351P3HIGHCVSS 8.1vr2≥ 6.2.9200.0, < 6.2.9200.243142023-06-14
CVE-2023-29351 [HIGH] CWE-59 CVE-2023-29351: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2020-1239P3HIGHCVSS 8.8vr22020-06-09
CVE-2020-1239 [HIGH] CVE-2020-1239: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238.
nvd
CVE-2021-33754P3HIGHCVSS 8.0vr2≥ 6.2.0, < 6.2.9200.234092021-07-14
CVE-2021-33754 [HIGH] CVE-2021-33754: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase