Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 84 of 201
CVE-2026-33834P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-33834 [HIGH] CWE-284 CVE-2026-33834: Improper access control in Windows Event Logging Service allows an authorized attacker to elevate pr
Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50491P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-50491 [HIGH] CWE-125 CVE-2026-50491: Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privilege
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26183P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-26183 [HIGH] CWE-284 CVE-2026-26183: Improper access control in Windows RPC API allows an authorized attacker to elevate privileges local
Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58714P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.257222025-10-14
CVE-2025-58714 [HIGH] CWE-284 CVE-2025-58714: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attack
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34338P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-34338 [HIGH] CWE-416 CVE-2026-34338: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40382P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260792026-05-12
CVE-2026-40382 [HIGH] CWE-416 CVE-2026-40382: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50435P3HIGHCVSS 7.8vr22026-07-14
CVE-2026-50435 [HIGH] CWE-126 CVE-2026-50435: Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges local
Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56182P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-56182 [HIGH] CWE-122 CVE-2026-56182: Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges l
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-27920P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-27920 [HIGH] CWE-822 CVE-2026-27920: Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an author
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2016-0018P3HIGHCVSS 7.3vr22016-01-13
CVE-2016-0018 [HIGH] CWE-426 CVE-2016-0018: Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 151
Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
nvd
CVE-2022-24547P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.236792022-04-15
CVE-2022-24547 [HIGH] CVE-2022-24547: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2026-27910P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.260262026-04-14
CVE-2026-27910 [HIGH] CWE-280 CVE-2026-27910: Improper handling of insufficient permissions or privileges in Windows Installer allows an authorize
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54989P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-54989 [HIGH] CWE-416 CVE-2026-54989: Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attack
Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54119P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.262262026-07-14
CVE-2026-54119 [HIGH] CWE-835 CVE-2026-54119: Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unautho
Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-29066P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.248212024-04-09
CVE-2024-29066 [HIGH] CWE-367 CVE-2024-29066: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2023-35350P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35350 [HIGH] CWE-122 CVE-2023-35350: Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
nvd
CVE-2023-32033P3HIGHCVSS 7.2vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-32033 [HIGH] CWE-416 CVE-2023-32033: Microsoft Failover Cluster Remote Code Execution Vulnerability
Microsoft Failover Cluster Remote Code Execution Vulnerability
nvd
CVE-2022-44675P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.240182022-12-13
CVE-2022-44675 [HIGH] CVE-2022-44675: Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-1599MEDIUMCVSS 5.5ExploitedRansomware≥ 6.2.0, < publication2020-11-11
CVE-2020-1599 [MEDIUM] Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
cvelistv5
CVE-2019-0877P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0877 [HIGH] CVE-2019-0877: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0879.
nvd