Msrc Windows Server 2012 vulnerabilities

3,255 known vulnerabilities affecting msrc/windows_server_2012.

Total CVEs
3,255
CISA KEV
133
actively exploited
Public exploits
200
Exploited in wild
124
Severity breakdown
CRITICAL83HIGH2162MEDIUM978LOW32

Vulnerabilities

Page 1 of 163
CVE-2026-24289HIGHCVSS 7.82026-03-10
CVE-2026-24289 [HIGH] CWE-416 Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability Description: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows Kernel: Windows Kernel Microsoft: Microsoft Customer Action
msrc
CVE-2026-24294HIGHCVSS 7.82026-03-10
CVE-2026-24294 [HIGH] CWE-287 Windows SMB Server Elevation of Privilege Vulnerability Windows SMB Server Elevation of Privilege Vulnerability Description: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows SMB Server: Windows SMB Server Microsof
msrc
CVE-2026-23673HIGHCVSS 7.82026-03-10
CVE-2026-23673 [HIGH] CWE-125 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability Description: Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
msrc
CVE-2026-25171HIGHCVSS 7.02026-03-10
CVE-2026-25171 [HIGH] CWE-416 Windows Authentication Elevation of Privilege Vulnerability Windows Authentication Elevation of Privilege Vulnerability Description: Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition. FAQ: What privi
msrc
CVE-2026-26128HIGHCVSS 7.82026-03-10
CVE-2026-26128 [HIGH] CWE-287 Windows SMB Server Elevation of Privilege Vulnerability Windows SMB Server Elevation of Privilege Vulnerability Description: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows SMB Server: Windows SMB Server Microsof
msrc
CVE-2026-25181HIGHCVSS 7.52026-03-10
CVE-2026-25181 [HIGH] CWE-125 GDI+ Information Disclosure Vulnerability GDI+ Information Disclosure Vulnerability Description: Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network. FAQ: What type of information could be disclosed by this vulnerability? A successful exploitation can occur within browser or other applications processing metafiles, resulting in an information disclosure where memory values from the current process are leaked to
msrc
CVE-2026-26111HIGHCVSS 8.02026-03-10
CVE-2026-26111 [HIGH] CWE-190 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Description: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. FAQ: How could an attacker exploit this vulnerability? An attacker authenticated on the domain could exploit this vulnerability by tricking
msrc
CVE-2026-25174HIGHCVSS 7.82026-03-10
CVE-2026-25174 [HIGH] CWE-125 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability Windows Extensible File Allocation Table Elevation of Privilege Vulnerability Description: Out-of-bounds read in Windows Extensible File Allocation allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privil
msrc
CVE-2026-25176HIGHCVSS 7.82026-03-10
CVE-2026-25176 [HIGH] CWE-284 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Description: Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerabilit
msrc
CVE-2026-23668HIGHCVSS 7.02026-03-10
CVE-2026-23668 [HIGH] CWE-362 Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability Description: Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation o
msrc
CVE-2026-23672HIGHCVSS 7.82026-03-10
CVE-2026-23672 [HIGH] CWE-125 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows Universal Disk Format File System Driver (UDFS): Windows Universal Disk Format File Sys
msrc
CVE-2026-24285HIGHCVSS 7.02026-03-10
CVE-2026-24285 [HIGH] CWE-416 Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Description: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited this vulnerability could gain administrator privileges. FAQ: Is the Preview Pane an attack vector for this vulnerability? No, the Previ
msrc
CVE-2026-25175HIGHCVSS 7.82026-03-10
CVE-2026-25175 [HIGH] CWE-125 Windows NTFS Elevation of Privilege Vulnerability Windows NTFS Elevation of Privilege Vulnerability Description: Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows NTFS: Windows NTFS Microsoft: Microsoft Customer Action Requi
msrc
CVE-2026-24291HIGHCVSS 7.82026-03-10
CVE-2026-24291 [HIGH] CWE-732 Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability Description: Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attac
msrc
CVE-2026-25179HIGHCVSS 7.02026-03-10
CVE-2026-25179 [HIGH] CWE-1287 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Description: Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exp
msrc
CVE-2026-25188HIGHCVSS 8.82026-03-10
CVE-2026-25188 [HIGH] CWE-122 Windows Telephony Service Elevation of Privilege Vulnerability Windows Telephony Service Elevation of Privilege Vulnerability Description: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. FAQ:
msrc
CVE-2026-25173HIGHCVSS 8.02026-03-10
CVE-2026-25173 [HIGH] CWE-190 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Description: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. FAQ: How could an attacker exploit this vulnerability? An attacker authenticated on the domain could exploit this vulnerability by tricking
msrc
CVE-2026-25187HIGHCVSS 7.82026-03-10
CVE-2026-25187 [HIGH] CWE-59 Winlogon Elevation of Privilege Vulnerability Winlogon Elevation of Privilege Vulnerability Description: Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Winlogon: Winlogon Microsoft: Microsoft
msrc
CVE-2026-25190HIGHCVSS 7.82026-03-10
CVE-2026-25190 [HIGH] CWE-426 GDI Remote Code Execution Vulnerability GDI Remote Code Execution Vulnerability Description: Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally. FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Executio
msrc
CVE-2026-23674HIGHCVSS 7.52026-03-10
CVE-2026-23674 [HIGH] CWE-41 MapUrlToZone Security Feature Bypass Vulnerability MapUrlToZone Security Feature Bypass Vulnerability Description: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited the vulnerability could bypass the MapURLToZone method. FAQ: The Security
msrc
1 / 163Next →
Msrc Windows Server 2012 vulnerabilities | cvebase