Windows Server 2012
by Microsoft
CVEs (4,890)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-21235 | Hig | 0.48 | 7.3 | 0.01 | Feb 10, 2026 | Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-20844 | Hig | 0.48 | 7.4 | 0.00 | Jan 13, 2026 | Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-20805 | Med | 0.48 | 5.5 | 0.05 | KEV | Jan 13, 2026 | Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. | |
| CVE-2025-55687 | Hig | 0.48 | 7.4 | 0.00 | Oct 14, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-55335 | Hig | 0.48 | 7.4 | 0.00 | Oct 14, 2025 | Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-48004 | Hig | 0.48 | 7.4 | 0.02 | Oct 14, 2025 | Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-54103 | Hig | 0.48 | 7.4 | 0.00 | Sep 9, 2025 | Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-49690 | Hig | 0.48 | 7.4 | 0.00 | Jul 8, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-24991 | Med | 0.48 | 5.5 | 0.02 | KEV | Mar 11, 2025 | Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. | |
| CVE-2025-21331 | Hig | 0.48 | 7.3 | 0.01 | Jan 14, 2025 | Windows Installer Elevation of Privilege Vulnerability | ||
| CVE-2024-49107 | Hig | 0.48 | 7.3 | 0.02 | Dec 12, 2024 | WmsRepair Service Elevation of Privilege Vulnerability | ||
| CVE-2024-43553 | Hig | 0.48 | 7.4 | 0.01 | Oct 8, 2024 | NT OS Kernel Elevation of Privilege Vulnerability | ||
| CVE-2024-43552 | Hig | 0.48 | 7.3 | 0.01 | Oct 8, 2024 | Windows Shell Remote Code Execution Vulnerability | ||
| CVE-2024-43550 | Hig | 0.48 | 7.4 | 0.01 | Oct 8, 2024 | Windows Secure Channel Spoofing Vulnerability | ||
| CVE-2024-43529 | Hig | 0.48 | 7.3 | 0.01 | Oct 8, 2024 | Windows Print Spooler Elevation of Privilege Vulnerability | ||
| CVE-2024-43495 | Hig | 0.48 | 7.3 | 0.01 | Sep 10, 2024 | Windows libarchive Remote Code Execution Vulnerability | ||
| CVE-2024-43454 | Hig | 0.48 | 7.1 | 0.22 | Sep 10, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | ||
| CVE-2024-38217 | Med | 0.48 | 5.4 | 0.10 | KEV | Sep 10, 2024 | Windows Mark of the Web Security Feature Bypass Vulnerability | |
| CVE-2024-38202 | Hig | 0.48 | 7.3 | 0.02 | Aug 8, 2024 | Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security… | ||
| CVE-2024-38033 | Hig | 0.48 | 7.3 | 0.01 | Jul 9, 2024 | PowerShell Elevation of Privilege Vulnerability |
- risk 0.48cvss 7.3epss 0.01
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 5.5epss 0.05
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
- risk 0.48cvss 7.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.02
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 7.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
- risk 0.48cvss 5.5epss 0.02
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
- risk 0.48cvss 7.3epss 0.01
Windows Installer Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.02
WmsRepair Service Elevation of Privilege Vulnerability
- risk 0.48cvss 7.4epss 0.01
NT OS Kernel Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
Windows Shell Remote Code Execution Vulnerability
- risk 0.48cvss 7.4epss 0.01
Windows Secure Channel Spoofing Vulnerability
- risk 0.48cvss 7.3epss 0.01
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
Windows libarchive Remote Code Execution Vulnerability
- risk 0.48cvss 7.1epss 0.22
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- risk 0.48cvss 5.4epss 0.10
Windows Mark of the Web Security Feature Bypass Vulnerability
- risk 0.48cvss 7.3epss 0.02
Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security…
- risk 0.48cvss 7.3epss 0.01
PowerShell Elevation of Privilege Vulnerability
Page 137 of 245