cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 8 of 201
CVE-2015-1769P2MEDIUMCVSS 6.6KEVvr22015-08-15
CVE-2015-1769 [MEDIUM] CWE-264 CVE-2015-1769: Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of
nvd
CVE-2019-0703P2MEDIUMCVSS 6.5KEVvr22019-04-09
CVE-2019-0703 [MEDIUM] CVE-2019-0703: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.
nvd
CVE-2025-24984P2MEDIUMCVSS 4.6KEVvr2≥ 6.2.9200.0, < 6.2.9200.253682025-03-11
CVE-2025-24984 [MEDIUM] CWE-532 CVE-2025-24984: Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-41089P1CRITICALCVSS 9.8ExploitedPoCvr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-41089 [CRITICAL] CWE-121 CVE-2026-41089: Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-26809P1CRITICALCVSS 9.8ExploitedPoCRansomwarevr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-26809 [CRITICAL] CVE-2022-26809: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2020-0609P1CRITICALCVSS 9.8ExploitedPoCRansomwarevr22020-01-14
CVE-2020-0609 [CRITICAL] CVE-2020-0609: A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.
nvd
CVE-2020-0610P1CRITICALCVSS 9.8ExploitedPoCRansomwarevr22020-01-14
CVE-2020-0610 [CRITICAL] CVE-2020-0610: A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.
nvd
CVE-2022-30136P1CRITICALCVSS 9.8ExploitedPoCvr2≥ 6.2.9200.0, < 6.2.9200.237362022-06-15
CVE-2022-30136 [CRITICAL] CVE-2022-30136: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2022-34721P1CRITICALCVSS 9.8ExploitedPoCvr2≥ 6.2.9200.0, < 6.2.9200.238652022-09-13
CVE-2022-34721 [CRITICAL] CVE-2022-34721: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2018-3639P1MEDIUMCVSS 5.5ExploitedPoCRansomwarevr22018-05-22
CVE-2018-3639 [MEDIUM] CWE-203 CVE-2018-3639: Systems with microprocessors utilizing speculative execution and speculative execution of memory rea Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
nvd
CVE-2021-40449HIGHCVSS 7.8KEVPoCRansomware≥ 6.2.0, < 6.2.9200.234902021-10-13
CVE-2021-40449 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-36942HIGHCVSS 7.5KEVPoCRansomware≥ 6.2.0, < 6.2.9200.234352021-08-12
CVE-2021-36942 [HIGH] Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability
cvelistv5
CVE-2015-0096P2CRITICALCVSS 9.3ExploitedPoCvr22015-03-11
CVE-2015-0096 [CRITICAL] CWE-426 CVE-2015-0096: Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading duri
nvd
CVE-2023-29336HIGHCVSS 7.8KEVPoC≥ 6.2.9200.0, < 6.2.9200.242662023-05-09
CVE-2023-29336 [HIGH] CWE-416 Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2019-1040P1MEDIUMCVSS 5.3ExploitedPoCvr2≥ 6.2.9200.0, < publication2019-06-12
CVE-2019-1040 [MEDIUM] CVE-2019-1040: A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to s A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the
nvd
CVE-2021-31956HIGHCVSS 7.8KEVPoC≥ 6.2.0, < 6.2.9200.233722021-06-08
CVE-2021-31956 [HIGH] Windows NTFS Elevation of Privilege Vulnerability Windows NTFS Elevation of Privilege Vulnerability Windows NTFS Elevation of Privilege Vulnerability
cvelistv5
CVE-2016-3225P2HIGHCVSS 7.8ExploitedPoCvr22016-06-16
CVE-2016-3225 [HIGH] CWE-264 CVE-2016-3225: The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application that forwards an authentication request to an unintended service, aka "Windows SMB Server El
nvd
CVE-2025-24071P1MEDIUMCVSS 6.5ExploitedPoCvr22025-03-11
CVE-2025-24071 [MEDIUM] CWE-200 CVE-2025-24071: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-30090P1HIGHCVSS 7.0ExploitedPoCRansomwarevr2≥ 6.2.9200.0, < 6.2.9200.249192024-06-11
CVE-2024-30090 [HIGH] CWE-822 CVE-2024-30090: Microsoft Streaming Service Elevation of Privilege Vulnerability Microsoft Streaming Service Elevation of Privilege Vulnerability
nvd
CVE-2014-6321P1CRITICALCVSS 10.0Exploitedvr22014-11-11
CVE-2014-6321 [CRITICAL] CWE-94 CVE-2014-6321: Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1 Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via crafted packets, aka "Microsoft Schannel Remote Code Execution Vulnerability."
nvd