Windows Server 2012
by Microsoft
CVEs (4,890)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24497 | Cri | 0.66 | 9.8 | 0.35 | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2022-24491 | Cri | 0.66 | 9.8 | 0.33 | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability | ||
| CVE-2021-24074 | Cri | 0.66 | 9.8 | 0.26 | Feb 25, 2021 | Windows TCP/IP Remote Code Execution Vulnerability | ||
| CVE-2020-1464 | Hig | 0.66 | 7.8 | 0.39 | KEV | Aug 17, 2020 | A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features… | |
| CVE-2020-0683 | Hig | 0.66 | 7.8 | 0.08 | KEV | Feb 11, 2020 | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686. | |
| CVE-2019-0863 | Hig | 0.66 | 7.8 | 0.05 | KEV | May 16, 2019 | An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. | |
| CVE-2019-0725 | Cri | 0.66 | 9.8 | 0.27 | May 16, 2019 | A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'. | ||
| CVE-2017-8686 | Cri | 0.66 | 9.8 | 0.25 | Sep 13, 2017 | The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows… | ||
| CVE-2017-8589 | Cri | 0.66 | 9.8 | 0.24 | Jul 11, 2017 | Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in… | ||
| CVE-2016-3227 | Cri | 0.66 | 9.8 | 0.41 | Jun 16, 2016 | Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability." | ||
| CVE-2016-3213 | Hig | 0.66 | 8.8 | 0.62 | Jun 16, 2016 | The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 through 11 has an… | ||
| CVE-2015-2387 | Hig | 0.66 | 7.8 | 0.35 | KEV | Jul 14, 2015 | ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges… | |
| CVE-2025-47981 | Cri | 0.65 | 9.8 | 0.33 | Jul 8, 2025 | Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-30397 | Hig | 0.65 | 7.5 | 0.27 | KEV | May 13, 2025 | Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | |
| CVE-2023-36397 | Cri | 0.65 | 9.8 | 0.18 | Nov 14, 2023 | Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | ||
| CVE-2023-21692 | Cri | 0.65 | 9.8 | 0.21 | Feb 14, 2023 | Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | ||
| CVE-2022-26925 | Hig | 0.65 | 8.1 | 0.11 | KEV | May 10, 2022 | Windows LSA Spoofing Vulnerability | |
| CVE-2021-26432 | Cri | 0.65 | 9.8 | 0.11 | Aug 12, 2021 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | ||
| CVE-2021-33742 | Hig | 0.65 | 7.5 | 0.59 | KEV | Jun 8, 2021 | Windows MSHTML Platform Remote Code Execution Vulnerability | |
| CVE-2021-26897 | Cri | 0.65 | 9.8 | 0.12 | Mar 11, 2021 | Windows DNS Server Remote Code Execution Vulnerability |
- risk 0.66cvss 9.8epss 0.35
Windows Network File System Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.33
Windows Network File System Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.26
Windows TCP/IP Remote Code Execution Vulnerability
- risk 0.66cvss 7.8epss 0.39
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features…
- risk 0.66cvss 7.8epss 0.08
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.
- risk 0.66cvss 7.8epss 0.05
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
- risk 0.66cvss 9.8epss 0.27
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
- risk 0.66cvss 9.8epss 0.25
The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows…
- risk 0.66cvss 9.8epss 0.24
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way that Windows Search handles objects in…
- risk 0.66cvss 9.8epss 0.41
Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."
- risk 0.66cvss 8.8epss 0.62
The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 through 11 has an…
- risk 0.66cvss 7.8epss 0.35
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges…
- risk 0.65cvss 9.8epss 0.33
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 7.5epss 0.27
Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
- risk 0.65cvss 9.8epss 0.18
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.21
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- risk 0.65cvss 8.1epss 0.11
Windows LSA Spoofing Vulnerability
- risk 0.65cvss 9.8epss 0.11
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
- risk 0.65cvss 7.5epss 0.59
Windows MSHTML Platform Remote Code Execution Vulnerability
- risk 0.65cvss 9.8epss 0.12
Windows DNS Server Remote Code Execution Vulnerability
Page 7 of 245