Microsoft Windows Server 2012 vulnerabilities
4,005 known vulnerabilities affecting microsoft/windows_server_2012.
Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55
Vulnerabilities
Page 86 of 201
CVE-2016-3263P3MEDIUMCVSS 5.5vr22016-10-14
CVE-2016-3263 [MEDIUM] CVE-2016-3263: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007
nvd
CVE-2024-49019P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.251652024-11-12
CVE-2024-49019 [HIGH] CWE-1390 CVE-2024-49019: Active Directory Certificate Services Elevation of Privilege Vulnerability
Active Directory Certificate Services Elevation of Privilege Vulnerability
nvd
CVE-2022-35793P3HIGHCVSS 7.3vr2≥ 6.2.9200.0, < 6.2.9200.238172022-08-09
CVE-2022-35793 [HIGH] CVE-2022-35793: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-26931P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.237142022-05-10
CVE-2022-26931 [HIGH] CVE-2022-26931: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-38127P3HIGHCVSS 7.8fixed in 6.2.9200.25031vr2+1 more2024-08-13
CVE-2024-38127 [HIGH] CWE-126 CVE-2024-38127: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2021-28315P3HIGHCVSS 7.8vr2≥ 6.2.0, < publication2021-04-13
CVE-2021-28315 [HIGH] CVE-2021-28315: Windows Media Video Decoder Remote Code Execution Vulnerability
Windows Media Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2022-30209P3HIGHCVSS 7.4vr2≥ 6.2.9200.0, < 6.2.9200.237712022-07-12
CVE-2022-30209 [HIGH] CVE-2022-30209: Windows IIS Server Elevation of Privilege Vulnerability
Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2025-27470P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-27470 [HIGH] CWE-400 CVE-2025-27470: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26652P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-26652 [HIGH] CWE-400 CVE-2025-26652: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27479P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.254232025-04-08
CVE-2025-27479 [HIGH] CWE-410 CVE-2025-27479: Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over
Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21174P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-21174 [HIGH] CWE-400 CVE-2025-21174: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27486P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-27486 [HIGH] CWE-400 CVE-2025-27486: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27485P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-27485 [HIGH] CWE-400 CVE-2025-27485: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26680P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-26680 [HIGH] CWE-400 CVE-2025-26680: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2016-3370P3MEDIUMCVSS 6.5vr22016-09-14
CVE-2016-3370 [MEDIUM] CWE-200 CVE-2016-3370: The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3374.
nvd
CVE-2024-38245P3HIGHCVSS 7.8vr2≥ 6.2.9200.0, < 6.2.9200.250732024-09-10
CVE-2024-38245 [HIGH] CWE-20 CVE-2024-38245: Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-33068P3HIGHCVSS 7.5vr22025-06-10
CVE-2025-33068 [HIGH] CWE-400 CVE-2025-33068: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-21363P3HIGHCVSS 7.8≥ 6.2.9200.0, < 6.2.9200.247102024-02-13
CVE-2024-21363 [HIGH] CWE-843 CVE-2024-21363: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2026-20875P3HIGHCVSS 7.5vr2≥ 6.2.9200.0, < 6.2.9200.258682026-01-13
CVE-2026-20875 [HIGH] CWE-476 CVE-2026-20875: Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an una
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2016-3333P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-3333 [HIGH] CVE-2016-3333: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd