Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 81 of 201
CVE-2020-16927P3HIGHCVSS 7.5vr22020-10-16
CVE-2020-16927 [HIGH] CVE-2020-16927: <p>A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connec
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on the target system to stop responding.
To exploit this vulnerability, an attacker would need to run a sp
nvd
CVE-2020-1407P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1407 [HIGH] CVE-2020-1407: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1401.
nvd
CVE-2014-0316P3HIGHCVSS 7.5vr22014-08-12
CVE-2014-0316 [HIGH] CWE-399 CVE-2014-0316: Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server
Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (memory consumption) and bypass the ASLR protection mechanism via a crafted client that sends messages
nvd
CVE-2014-6317P3HIGHCVSS 7.1vr22014-11-11
CVE-2014-6317 [HIGH] CWE-129 CVE-2014-6317: Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Win
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font, aka "Denial
nvd
CVE-2016-3374P3MEDIUMCVSS 6.5vr22016-09-14
CVE-2016-3374 [MEDIUM] CVE-2016-3374: The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.
nvd
CVE-2019-1206P3HIGHCVSS 7.5vr2≥ 6.2.0, < publication2019-08-14
CVE-2019-1206 [HIGH] CWE-787 CVE-2019-1206: A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends s
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server. An attacker who successfully exploited the vulnerability could cause the DHCP service to become nonresponsive.
To exploit the vulnerability, an attacker could send a specially crafted packet to a DHCP se
nvd
CVE-2022-22000P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.236052022-02-09
CVE-2022-22000 [HIGH] CVE-2022-22000: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-30394P3MEDIUMCVSS 5.9vr2≥ 6.2.9200.0, < 6.2.9200.254752025-05-13
CVE-2025-30394 [MEDIUM] CWE-591 CVE-2025-30394: Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unaut
Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2017-8591P3HIGHCVSS 7.8vr22017-08-08
CVE-2017-8591 [HIGH] CVE-2017-8591: Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, W
Windows Input Method Editor (IME) in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an remote code execution vulnerability when it fails to properly handle objects in memory, aka "Windows IME Remote Code Execution Vulnerability".
nvd
CVE-2017-8495P3HIGHCVSS 7.5vr22017-07-11
CVE-2017-8495 [HIGH] CWE-287 CVE-2017-8495: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extended Protection for Authentication when Kerberos fails to prevent tampering with the SNAME field during ticket exchange, aka "Kerberos SNA
nvd
CVE-2017-8714P3HIGHCVSS 7.8vr22017-09-13
CVE-2017-8714 [HIGH] CWE-20 CVE-2017-8714: The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10
The Windows Hyper-V component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2,, Windows 10 1607, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Remote Desktop Virtual Host Remote Code Execution Vulnerability".
nvd
CVE-2025-21420P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.253172025-02-11
CVE-2025-21420 [HIGH] CWE-59 CVE-2025-21420: Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
nvd
CVE-2023-21812P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.241162023-02-14
CVE-2023-21812 [HIGH] CWE-122 CVE-2023-21812: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-22026P3HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.237712022-07-12
CVE-2022-22026 [HIGH] CWE-787 CVE-2022-22026: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2026-35422P3MEDIUMCVSS 6.5vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-35422 [MEDIUM] CWE-288 CVE-2026-35422: Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized atta
Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
nvd
CVE-2017-8588P3HIGHCVSS 7.0vr22017-07-11
CVE-2017-8588 [HIGH] CVE-2017-8588: Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it parses specially crafted files, aka "WordPad Remote Code Execution Vulnerability".
nvd
CVE-2017-8633P3HIGHCVSS 7.5vr22017-08-08
CVE-2017-8633 [HIGH] CWE-863 CVE-2017-8633: Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win
Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability, aka "Windows Error Reporting Elevation of Privilege Vulnerability".
nvd
CVE-2022-21843P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21843 [HIGH] CVE-2022-21843: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2022-35755P3HIGHCVSS 7.3vr22023-05-31
CVE-2022-35755 [HIGH] CVE-2022-35755: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2023-36425P3HIGHCVSS 8.0vr2≥ 6.2.9200.0, < 6.2.9200.245692023-11-14
CVE-2023-36425 [HIGH] CWE-122 CVE-2023-36425: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd