Windows Server 2012
by Microsoft
CVEs (4,890)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-49794 | Med | 0.00 | 4.6 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. | ||
| CVE-2026-49791 | Hig | 0.00 | 7.1 | 0.00 | Jul 14, 2026 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49790 | Hig | 0.00 | 7.3 | 0.00 | Jul 14, 2026 | Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | ||
| CVE-2026-49789 | Hig | 0.00 | 7.3 | 0.00 | Jul 14, 2026 | Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49184 | Hig | 0.00 | 8.4 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-49181 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-49180 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally. | ||
| CVE-2026-49178 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | ||
| CVE-2026-49164 | Hig | 0.00 | 8.1 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-48564 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-44806 | Med | 0.00 | 5.3 | 0.01 | Jul 14, 2026 | Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-42990 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42975 | Hig | 0.00 | 8.0 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | ||
| CVE-2026-40378 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-34346 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | ||
| CVE-2026-33842 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | ||
| CVE-2015-6126 | 0.00 | — | 0.02 | Dec 9, 2015 | Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511… | |||
| CVE-2015-6113 | 0.00 | — | 0.02 | Nov 11, 2015 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass intended filesystem permissions by leveraging… | |||
| CVE-2015-6112 | 0.00 | — | 0.03 | Nov 11, 2015 | SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate… | |||
| CVE-2015-6109 | 0.00 | — | 0.03 | Nov 11, 2015 | The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory… |
- risk 0.00cvss 4.6epss 0.00
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
- risk 0.00cvss 7.1epss 0.00
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.3epss 0.00
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
- risk 0.00cvss 7.3epss 0.00
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.4epss 0.00
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.5epss 0.01
Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 5.5epss 0.00
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- risk 0.00cvss 8.8epss 0.01
Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
- risk 0.00cvss 8.1epss 0.01
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
- risk 0.00cvss 5.3epss 0.01
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 8.0epss 0.01
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.
- risk 0.00cvss 7.5epss 0.01
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 5.5epss 0.00
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.00
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
- CVE-2015-6126Dec 9, 2015risk 0.00cvss —epss 0.02
Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511…
- CVE-2015-6113Nov 11, 2015risk 0.00cvss —epss 0.02
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass intended filesystem permissions by leveraging…
- CVE-2015-6112Nov 11, 2015risk 0.00cvss —epss 0.03
SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate…
- CVE-2015-6109Nov 11, 2015risk 0.00cvss —epss 0.03
The kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via a crafted application, aka "Windows Kernel Memory…
Page 241 of 245