Msrc Windows Server 2012 vulnerabilities

3,255 known vulnerabilities affecting msrc/windows_server_2012.

Total CVEs
3,255
CISA KEV
133
actively exploited
Public exploits
200
Exploited in wild
124
Severity breakdown
CRITICAL83HIGH2162MEDIUM978LOW32

Vulnerabilities

Page 60 of 163
CVE-2023-28220HIGHCVSS 8.12023-04-11
CVE-2023-28220 [HIGH] CWE-591 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition. FAQ: How could an attacker exploit this vulnerability? An unauthenticated attacker could send a specially crafted protocol message to
msrc
CVE-2023-28244HIGHCVSS 8.12023-04-11
CVE-2023-28244 [HIGH] CWE-327 Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? The attacker must inject themselves into the logical network path between the target and the resource requested by the victim to read or modify network communications. This is called a machine-in-the-middle (MITM) attack. FAQ: How could an att
msrc
CVE-2023-28216HIGHCVSS 7.02023-04-11
CVE-2023-28216 [HIGH] Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An a
msrc
CVE-2023-28218HIGHCVSS 7.02023-04-11
CVE-2023-28218 [HIGH] CWE-122 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition. FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerabi
msrc
CVE-2023-28275HIGHCVSS 8.82023-04-11
CVE-2023-28275 [HIGH] CWE-122 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An attacker could exploit the vulnerability by tricking an authenticated user (CVSS metric UI:R) into attempting to connect to a malicious SQL server via OLEDB (CVSS metric AV:N), which could result in the server receiving a malicious networking pack
msrc
CVE-2023-28237HIGHCVSS 7.82023-04-11
CVE-2023-28237 [HIGH] CWE-190 Windows Kernel Remote Code Execution Vulnerability Windows Kernel Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim ne
msrc
CVE-2023-28254HIGHCVSS 7.22023-04-11
CVE-2023-28254 [HIGH] CWE-122 Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires the attacker or targeted user to have specific elevated privileges. As is best practice, regular validation and audits of administrative groups should be conducted. Microsoft Windows DNS:
msrc
CVE-2023-21727HIGHCVSS 8.82023-04-11
CVE-2023-21727 [HIGH] CWE-122 Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? To exploit this vulnerability, an authenticated attacker would need to send a specially crafted RPC call to an RPC host. This could result in remote code execution on the server side with the same permissions as the RPC service. Windows RPC API: Windows RPC API Microsoft: Microso
msrc
CVE-2023-28247HIGHCVSS 7.52023-04-11
CVE-2023-28247 [HIGH] CWE-191 Windows Network File System Information Disclosure Vulnerability Windows Network File System Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the contents of Kernel memory. An attacker could read the contents of Kernel memory from a user mode process. Windows Network File System: Windows Network Fil
msrc
CVE-2023-28227HIGHCVSS 7.52023-04-11
CVE-2023-28227 [HIGH] CWE-122 Windows Bluetooth Driver Remote Code Execution Vulnerability Windows Bluetooth Driver Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability? Exploiting this vulnerability requires an attacker to be within proximity of the target system to send and receive radio transmissions. FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean
msrc
CVE-2023-24887HIGHCVSS 8.82023-04-11
CVE-2023-24887 [HIGH] CWE-191 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An authenticated attacker with normal privileges could send a modified XPS file to a shared printer, which can result in a remote code execution. Microsoft Printer Drivers: Microsoft Printer Drivers Microsoft: Microsoft Customer Action R
msrc
CVE-2023-28231HIGHCVSS 8.82023-04-11
CVE-2023-28231 [HIGH] CWE-122 DHCP Server Service Remote Code Execution Vulnerability DHCP Server Service Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires that an attacker will need to first gain access to the restricted network before running an attack. FAQ: How could an attacker exploit this vulnerability? An unauthenticated attacker c
msrc
CVE-2023-24884HIGHCVSS 8.82023-04-11
CVE-2023-24884 [HIGH] CWE-681 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An authenticated attacker with normal privileges could send a modified XPS file to a shared printer, which can result in a remote code execution. Microsoft Printer Drivers: Microsoft Printer Drivers Microsoft: Microsoft Customer Action R
msrc
CVE-2023-24885HIGHCVSS 8.82023-04-11
CVE-2023-24885 [HIGH] CWE-843 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An authenticated attacker with normal privileges could send a modified XPS file to a shared printer, which can result in a remote code execution. Microsoft Printer Drivers: Microsoft Printer Drivers Microsoft: Microsoft Customer Action R
msrc
CVE-2023-28217HIGHCVSS 7.52023-04-11
CVE-2023-28217 [HIGH] CWE-400 Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT): Windows Network Address Translation (NAT) Microsoft: Microsoft Customer Action Required: Yes Impact: Denial of Service Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation More Likely;DOS:N/A
msrc
CVE-2023-28293HIGHCVSS 7.8PoC2023-04-11
CVE-2023-28293 [HIGH] CWE-191 Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability Windows Kernel: Windows Kernel Microsoft: Microsoft Customer Action Required: Yes Impact: Elevation of Privilege Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5025229 Reference: https://support.microsoft.com/help/5025229 Ref
msrc
CVE-2023-28252HIGHCVSS 7.8KEVPoC2023-04-11
CVE-2023-28252 [HIGH] CWE-122 Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows Common Log File System Driver: Windows Common Log File System Driver Microsoft: Microsoft Customer Action Required: Yes
msrc
CVE-2023-24886HIGHCVSS 8.82023-04-11
CVE-2023-24886 [HIGH] CWE-908 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An authenticated attacker with normal privileges could send a modified XPS file to a shared printer, which can result in a remote code execution. Microsoft Printer Drivers: Microsoft Printer Drivers Microsoft: Microsoft Customer Action R
msrc
CVE-2023-28229HIGHCVSS 7.0KEV2023-04-11
CVE-2023-28229 [HIGH] CWE-591 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability Windows CNG Key Isolation Service Elevation of Privilege Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition. FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who suc
msrc
CVE-2023-28269MEDIUMCVSS 6.22023-04-11
CVE-2023-28269 [MEDIUM] CWE-122 Windows Boot Manager Security Feature Bypass Vulnerability Windows Boot Manager Security Feature Bypass Vulnerability FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could bypass Secure Boot to run unauthorized code. To be successful the attacker would need either physical access or administrator privileges. Windows Boot Manager: Windows Boot Manager Mi
msrc