cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 84 of 201
CVE-2026-33834P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-33834 [HIGH] CWE-284 CVE-2026-33834: Improper access control in Windows Event Logging Service allows an authorized attacker to elevate pr Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50491P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50491 [HIGH] CWE-125 CVE-2026-50491: Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privilege Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26183P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-26183 [HIGH] CWE-284 CVE-2026-26183: Improper access control in Windows RPC API allows an authorized attacker to elevate privileges local Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58714P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.257222025-10-14
CVE-2025-58714 [HIGH] CWE-284 CVE-2025-58714: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34338P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-34338 [HIGH] CWE-416 CVE-2026-34338: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40382P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-40382 [HIGH] CWE-416 CVE-2026-40382: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50435P3HIGHCVSS 7.8vr22026-07-14
CVE-2026-50435 [HIGH] CWE-126 CVE-2026-50435: Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges local Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56182P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-56182 [HIGH] CWE-122 CVE-2026-56182: Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges l Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27920P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-27920 [HIGH] CWE-822 CVE-2026-27920: Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an author Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2016-0018P3HIGHCVSS 7.3vr22016-01-13
CVE-2016-0018 [HIGH] CWE-426 CVE-2016-0018: Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 151 Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
nvd
CVE-2022-24547P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-24547 [HIGH] CVE-2022-24547: Windows Digital Media Receiver Elevation of Privilege Vulnerability Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2026-27910P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-27910 [HIGH] CWE-280 CVE-2026-27910: Improper handling of insufficient permissions or privileges in Windows Installer allows an authorize Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54989P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-54989 [HIGH] CWE-416 CVE-2026-54989: Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attack Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54119P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-54119 [HIGH] CWE-835 CVE-2026-54119: Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unautho Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-29066P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.248212024-04-09
CVE-2024-29066 [HIGH] CWE-367 CVE-2024-29066: Windows Distributed File System (DFS) Remote Code Execution Vulnerability Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2023-35350P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35350 [HIGH] CWE-122 CVE-2023-35350: Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
nvd
CVE-2023-32033P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-32033 [HIGH] CWE-416 CVE-2023-32033: Microsoft Failover Cluster Remote Code Execution Vulnerability Microsoft Failover Cluster Remote Code Execution Vulnerability
nvd
CVE-2022-44675P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.240182022-12-13
CVE-2022-44675 [HIGH] CVE-2022-44675: Windows Bluetooth Driver Elevation of Privilege Vulnerability Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-1599MEDIUMCVSS 5.5ExploitedRansomware≥ 6.2.0, < publication2020-11-11
CVE-2020-1599 [MEDIUM] Windows Spoofing Vulnerability Windows Spoofing Vulnerability Windows Spoofing Vulnerability
cvelistv5
CVE-2019-0877P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0877 [HIGH] CVE-2019-0877: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0879.
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase