Msrc Windows Server 2012 vulnerabilities
3,255 known vulnerabilities affecting msrc/windows_server_2012.
Total CVEs
3,255
CISA KEV
133
actively exploited
Public exploits
200
Exploited in wild
124
Severity breakdown
CRITICAL83HIGH2162MEDIUM978LOW32
Vulnerabilities
Page 9 of 163
CVE-2025-54091HIGHCVSS 7.82025-09-09
CVE-2025-54091 [HIGH] CWE-190 Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
Description: Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Role: Windows Hyper-V: Role: Windows Hyper-V
Micr
msrc
CVE-2025-54895HIGHCVSS 7.82025-09-09
CVE-2025-54895 [HIGH] CWE-190 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability
Description: Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited
msrc
CVE-2025-54911HIGHCVSS 7.32025-09-09
CVE-2025-54911 [HIGH] CWE-416 Windows BitLocker Elevation of Privilege Vulnerability
Windows BitLocker Elevation of Privilege Vulnerability
Description: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, user interaction is requi
msrc
CVE-2025-54099HIGHCVSS 7.02025-09-09
CVE-2025-54099 [HIGH] CWE-121 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Description: Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vu
msrc
CVE-2025-54110HIGHCVSS 8.82025-09-09
CVE-2025-54110 [HIGH] CWE-190 Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Description: Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, a successful explo
msrc
CVE-2025-54912HIGHCVSS 7.82025-09-09
CVE-2025-54912 [HIGH] CWE-416 Windows BitLocker Elevation of Privilege Vulnerability
Windows BitLocker Elevation of Privilege Vulnerability
Description: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
Windows BitLocker: Windows BitLocker
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catal
msrc
CVE-2025-54113HIGHCVSS 8.82025-09-09
CVE-2025-54113 [HIGH] CWE-122 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are none
msrc
CVE-2025-53798MEDIUMCVSS 6.52025-09-09
CVE-2025-53798 [MEDIUM] CWE-126 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are non
msrc
CVE-2025-53803MEDIUMCVSS 5.52025-09-09
CVE-2025-53803 [MEDIUM] CWE-209 Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
Description: Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of certain memory address within kernel space. Knowing the exact
msrc
CVE-2025-54094MEDIUMCVSS 6.72025-09-09
CVE-2025-54094 [MEDIUM] CWE-843 Windows Defender Firewall Service Elevation of Privilege Vulnerability
Windows Defender Firewall Service Elevation of Privilege Vulnerability
Description: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker could use this vulnerability to elevate p
msrc
CVE-2025-55225MEDIUMCVSS 6.52025-09-09
CVE-2025-55225 [MEDIUM] CWE-125 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could po
msrc
CVE-2025-54096MEDIUMCVSS 6.52025-09-09
CVE-2025-54096 [MEDIUM] CWE-125 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could po
msrc
CVE-2025-54097MEDIUMCVSS 6.52025-09-09
CVE-2025-54097 [MEDIUM] CWE-125 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Description: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are n
msrc
CVE-2025-53808MEDIUMCVSS 6.72025-09-09
CVE-2025-53808 [MEDIUM] CWE-843 Windows Defender Firewall Service Elevation of Privilege Vulnerability
Windows Defender Firewall Service Elevation of Privilege Vulnerability
Description: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker could use this vulnerability to elevate p
msrc
CVE-2025-53799MEDIUMCVSS 5.52025-09-09
CVE-2025-53799 [MEDIUM] CWE-908 Windows Imaging Component Information Disclosure Vulnerability
Windows Imaging Component Information Disclosure Vulnerability
Description: Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
FAQ: According to
msrc
CVE-2025-53804MEDIUMCVSS 5.52025-09-09
CVE-2025-53804 [MEDIUM] CWE-200 Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
FAQ: What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of certain memory address within kernel space. Knowing t
msrc
CVE-2025-54107MEDIUMCVSS 4.32025-09-09
CVE-2025-54107 [MEDIUM] CWE-41 MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
Description: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited the vulnerability could bypass the MapURLToZone method.
FAQ: The Securi
msrc
CVE-2025-54915MEDIUMCVSS 6.72025-09-09
CVE-2025-54915 [MEDIUM] CWE-843 Windows Defender Firewall Service Elevation of Privilege Vulnerability
Windows Defender Firewall Service Elevation of Privilege Vulnerability
Description: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker could use this vulnerability to elevate p
msrc
CVE-2025-54101MEDIUMCVSS 4.82025-09-09
CVE-2025-54101 [MEDIUM] CWE-416 Windows SMB Client Remote Code Execution Vulnerability
Windows SMB Client Remote Code Execution Vulnerability
Description: Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack vector is network (AV:N), user interaction is required (UI:R), and privileges required are low (PR:L). What does that mean for this vulnerability?
Exploitation of this vulnerability requires an au
msrc
CVE-2025-54104MEDIUMCVSS 6.72025-09-09
CVE-2025-54104 [MEDIUM] CWE-843 Windows Defender Firewall Service Elevation of Privilege Vulnerability
Windows Defender Firewall Service Elevation of Privilege Vulnerability
Description: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker could use this vulnerability to elevate p
msrc