Windows Server 2012
by Microsoft
CVEs (4,861)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20928 | Med | 0.30 | 4.6 | 0.00 | Apr 14, 2026 | Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack. | ||
| CVE-2026-20834 | Med | 0.30 | 4.6 | 0.01 | Jan 13, 2026 | Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | ||
| CVE-2026-20828 | Med | 0.30 | 4.6 | 0.01 | Jan 13, 2026 | Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2025-21215 | Med | 0.30 | 4.6 | 0.01 | Jan 14, 2025 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2025-21213 | Med | 0.30 | 4.6 | 0.01 | Jan 14, 2025 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2024-49087 | Med | 0.30 | 4.6 | 0.01 | Dec 12, 2024 | Windows Mobile Broadband Driver Information Disclosure Vulnerability | ||
| CVE-2024-21340 | Med | 0.30 | 4.6 | 0.01 | Feb 13, 2024 | Windows Kernel Information Disclosure Vulnerability | ||
| CVE-2022-21905 | Med | 0.30 | 4.6 | 0.01 | Jan 11, 2022 | Windows Hyper-V Security Feature Bypass Vulnerability | ||
| CVE-2022-21900 | Med | 0.30 | 4.6 | 0.01 | Jan 11, 2022 | Windows Hyper-V Security Feature Bypass Vulnerability | ||
| CVE-2026-32209 | Med | 0.29 | 4.4 | 0.00 | May 12, 2026 | Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally. | ||
| CVE-2026-20962 | Med | 0.29 | 4.4 | 0.00 | Jan 13, 2026 | Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-20825 | Med | 0.29 | 4.4 | 0.01 | Jan 13, 2026 | Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. | ||
| CVE-2025-24997 | Med | 0.29 | 4.4 | 0.01 | Mar 11, 2025 | Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally. | ||
| CVE-2024-21305 | Med | 0.29 | 4.4 | 0.02 | Jan 9, 2024 | Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | ||
| CVE-2023-36722 | Med | 0.29 | 4.4 | 0.01 | Oct 10, 2023 | Active Directory Domain Services Information Disclosure Vulnerability | ||
| CVE-2023-28276 | Med | 0.29 | 4.4 | 0.00 | Apr 11, 2023 | Windows Group Policy Security Feature Bypass Vulnerability | ||
| CVE-2022-22010 | Med | 0.29 | 4.4 | 0.03 | Mar 9, 2022 | Media Foundation Information Disclosure Vulnerability | ||
| CVE-2022-21894 | Med | 0.29 | 4.4 | 0.07 | Jan 11, 2022 | Secure Boot Security Feature Bypass Vulnerability | ||
| CVE-2021-41371 | Med | 0.29 | 4.4 | 0.01 | Nov 10, 2021 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | ||
| CVE-2021-38631 | Med | 0.29 | 4.4 | 0.02 | Nov 10, 2021 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
- risk 0.30cvss 4.6epss 0.00
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
- risk 0.30cvss 4.6epss 0.01
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
- risk 0.30cvss 4.6epss 0.01
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.30cvss 4.6epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.30cvss 4.6epss 0.01
Secure Boot Security Feature Bypass Vulnerability
- risk 0.30cvss 4.6epss 0.01
Windows Mobile Broadband Driver Information Disclosure Vulnerability
- risk 0.30cvss 4.6epss 0.01
Windows Kernel Information Disclosure Vulnerability
- risk 0.30cvss 4.6epss 0.01
Windows Hyper-V Security Feature Bypass Vulnerability
- risk 0.30cvss 4.6epss 0.01
Windows Hyper-V Security Feature Bypass Vulnerability
- risk 0.29cvss 4.4epss 0.00
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
- risk 0.29cvss 4.4epss 0.00
Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.01
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.
- risk 0.29cvss 4.4epss 0.01
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
- risk 0.29cvss 4.4epss 0.02
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
- risk 0.29cvss 4.4epss 0.01
Active Directory Domain Services Information Disclosure Vulnerability
- risk 0.29cvss 4.4epss 0.00
Windows Group Policy Security Feature Bypass Vulnerability
- risk 0.29cvss 4.4epss 0.03
Media Foundation Information Disclosure Vulnerability
- risk 0.29cvss 4.4epss 0.07
Secure Boot Security Feature Bypass Vulnerability
- risk 0.29cvss 4.4epss 0.01
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
- risk 0.29cvss 4.4epss 0.02
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Page 219 of 244