Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 73 of 201
CVE-2019-1183P3HIGHCVSS 8.8vr22019-08-14
CVE-2019-1183 [HIGH] CVE-2019-1183: This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by th
This information is being revised to indicate that this CVE (CVE-2019-1183) is fully mitigated by the security updates for the vulnerability discussed in CVE-2019-1194. No update is required.
nvd
CVE-2018-0746P4MEDIUMCVSS 4.7PoCvr22018-01-04
CVE-2018-0746 [MEDIUM] CVE-2018-0746: The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 160
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to the way memory addresses are handled, aka "Windows Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0745 and C
nvd
CVE-2022-38051P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.239202022-10-11
CVE-2022-38051 [HIGH] CVE-2022-38051: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-21307P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.246642024-01-09
CVE-2024-21307 [HIGH] CWE-416 CVE-2024-21307: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2019-0688P3HIGHCVSS 7.5vr22019-04-09
CVE-2019-0688 [HIGH] CWE-327 CVE-2019-0688: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles frag
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
nvd
CVE-2022-30140P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30140 [HIGH] CVE-2022-30140: Windows iSCSI Discovery Service Remote Code Execution Vulnerability
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2024-30022P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30022 [HIGH] CWE-197 CVE-2024-30022: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30024P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30024 [HIGH] CWE-197 CVE-2024-30024: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30023P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30023 [HIGH] CWE-197 CVE-2024-30023: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-26195P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.248212024-04-09
CVE-2024-26195 [HIGH] CWE-122 CVE-2024-26195: DHCP Server Service Remote Code Execution Vulnerability
DHCP Server Service Remote Code Execution Vulnerability
nvd
CVE-2024-26202P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.248212024-04-09
CVE-2024-26202 [HIGH] CWE-122 CVE-2024-26202: DHCP Server Service Remote Code Execution Vulnerability
DHCP Server Service Remote Code Execution Vulnerability
nvd
CVE-2025-32713P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.255222025-06-10
CVE-2025-32713 [HIGH] CWE-122 CVE-2025-32713: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-24474P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-24474 [HIGH] CVE-2022-24474: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2019-1246P3HIGHCVSS 7.8vr22019-09-11
CVE-2019-1246 [HIGH] CVE-2019-1246: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2026-25181P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.259732026-03-10
CVE-2026-25181 [HIGH] CWE-125 CVE-2026-25181: Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a ne
Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2024-38044P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.249752024-07-09
CVE-2024-38044 [HIGH] CWE-197 CVE-2024-38044: DHCP Server Service Remote Code Execution Vulnerability
DHCP Server Service Remote Code Execution Vulnerability
nvd
CVE-2016-3342P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-3342 [HIGH] CVE-2016-3342: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3340P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-3340 [HIGH] CVE-2016-3340: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3343P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-3343 [HIGH] CVE-2016-3343: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2026-32183P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-32183 [HIGH] CWE-77 CVE-2026-32183: Improper neutralization of special elements used in a command ('command injection') in Windows Snipp
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an unauthorized attacker to execute code locally.
nvd