Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 77 of 201
CVE-2021-26882P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-03-11
CVE-2021-26882 [HIGH] CVE-2021-26882: Remote Access API Elevation of Privilege Vulnerability
Remote Access API Elevation of Privilege Vulnerability
nvd
CVE-2023-23410P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.241682023-03-14
CVE-2023-23410 [HIGH] CWE-190 CVE-2023-23410: Windows HTTP.sys Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
nvd
CVE-2015-0009P4LOWCVSS 3.3PoCvr22015-02-11
CVE-2015-0009 [LOW] CWE-254 CVE-2015-0009: The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2,
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing requirement and trigger a revert-to-default ac
nvd
CVE-2017-11781P3HIGHCVSS 7.5vr22017-10-13
CVE-2017-11781 [HIGH] CWE-20 CVE-2017-11781: The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7
The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a denial of service vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB D
nvd
CVE-2025-26673P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.254232025-04-08
CVE-2025-26673 [HIGH] CWE-400 CVE-2025-26673: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27469P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.254232025-04-08
CVE-2025-27469 [HIGH] CWE-400 CVE-2025-27469: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2016-3348P3HIGHCVSS 7.8vr22016-09-14
CVE-2016-3348 [HIGH] CWE-264 CVE-2016-3348: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2020-1401P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1401 [HIGH] CVE-2020-1401: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1407.
nvd
CVE-2022-30149P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30149 [HIGH] CVE-2022-30149: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30143P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30143 [HIGH] CVE-2022-30143: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30146P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30146 [HIGH] CVE-2022-30146: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2017-0016P3MEDIUMCVSS 5.9vr22017-03-17
CVE-2017-0016 [MEDIUM] CWE-476 CVE-2017-0016: Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and
Microsoft Windows 10 Gold, 1511, and 1607; Windows 8.1; Windows RT 8.1; Windows Server 2012 R2, and Windows Server 2016 do not properly handle certain requests in SMBv2 and SMBv3 packets, which allows remote attackers to execute arbitrary code via a crafted SMBv2 or SMBv3 packet to the Server service, aka "SMBv2/SMBv3 Null Dereference Denial of Service
nvd
CVE-2025-47955P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.254752025-06-10
CVE-2025-47955 [HIGH] CWE-269 CVE-2025-47955: Improper privilege management in Windows Remote Access Connection Manager allows an authorized attac
Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26686P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.254232025-04-08
CVE-2025-26686 [HIGH] CWE-591 CVE-2025-26686: Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker
Sensitive data storage in improperly locked memory in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-30015P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30015 [HIGH] CWE-197 CVE-2024-30015: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30029P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30029 [HIGH] CWE-197 CVE-2024-30029: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30014P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.248682024-05-14
CVE-2024-30014 [HIGH] CWE-197 CVE-2024-30014: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2018-8251P3HIGHCVSS 7.5vr2v(Server Core installation)2018-06-14
CVE-2018-8251 [HIGH] CWE-787 CVE-2018-8251: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media Foundation Memory Corruption Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2026-20846P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.259232026-02-10
CVE-2026-20846 [HIGH] CWE-126 CVE-2026-20846: Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
Buffer over-read in Windows GDI+ allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-62455P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.258152025-12-09
CVE-2025-62455 [HIGH] CWE-20 CVE-2025-62455: Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privil
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd