VYPR

Windows Server 2012

by Microsoft

CVEs (4,890)

  • CVE-2025-48813MedOct 14, 2025
    risk 0.41cvss 6.3epss 0.00

    Use of a key past its expiration date in Virtual Secure Mode allows an authorized attacker to perform spoofing locally.

  • CVE-2024-28898MedApr 9, 2024
    risk 0.41cvss 6.3epss 0.01

    Secure Boot Security Feature Bypass Vulnerability

  • CVE-2022-21928MedJan 11, 2022
    risk 0.41cvss 6.3epss 0.01

    Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

  • CVE-2021-34500MedJul 14, 2021
    risk 0.41cvss 6.3epss 0.03

    Windows Kernel Memory Information Disclosure Vulnerability

  • CVE-2019-1053MedJun 12, 2019
    risk 0.41cvss 6.3epss 0.01

    An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require…

  • CVE-2019-0986MedJun 12, 2019
    risk 0.41cvss 6.3epss 0.02

    An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker…

  • CVE-2018-0833MedFeb 15, 2018
    risk 0.41cvss 5.3epss 0.40

    The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability".

  • CVE-2017-0055MedMar 17, 2017
    risk 0.41cvss 6.1epss 0.16

    Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site…

  • CVE-2016-3302MedSep 14, 2016
    risk 0.41cvss 6.3epss 0.02

    Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code via a (1) crafted Wi-Fi…

  • CVE-2026-40380MedMay 12, 2026
    risk 0.40cvss 6.2epss 0.00

    Heap-based buffer overflow in Volume Manager Extension Driver allows an authorized attacker to execute code with a physical attack.

  • CVE-2026-32088MedApr 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Biometric Service allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2026-32072MedApr 14, 2026
    risk 0.40cvss 6.2epss 0.00

    Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

  • CVE-2026-26169MedApr 14, 2026
    risk 0.40cvss 6.1epss 0.02

    Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.

  • CVE-2026-25169MedMar 10, 2026
    risk 0.40cvss 6.2epss 0.00

    Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

  • CVE-2026-25168MedMar 10, 2026
    risk 0.40cvss 6.2epss 0.00

    Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.

  • CVE-2026-20821MedJan 13, 2026
    risk 0.40cvss 6.2epss 0.01

    Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

  • CVE-2026-20818MedJan 13, 2026
    risk 0.40cvss 6.2epss 0.01

    Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.

  • CVE-2025-59258MedOct 14, 2025
    risk 0.40cvss 6.2epss 0.01

    Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

  • CVE-2025-55338MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.03

    Missing Ability to Patch ROM Code in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

  • CVE-2025-55333MedOct 14, 2025
    risk 0.40cvss 6.1epss 0.01

    Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

Page 184 of 245