VendorsMicrosoftwindows_server_2012any version
Vulnerabilities

Microsoft Windows Server 2012 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4774CVEs
CVE-2019-0635
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-03-06 · Modified
6.2EPSS 0.024
CVE-2019-1399
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1310.
Published 2019-11-12 · Modified
6.2EPSS 0.017
CVE-2021-33765
Windows Installer Spoofing Vulnerability
Published 2021-07-14 · Modified
6.2EPSS 0.007
CVE-2021-26413
Windows Installer Spoofing Vulnerability
Published 2021-04-13 · Modified
6.2EPSS 0.007
CVE-2026-20821
Remote Procedure Call Information Disclosure Vulnerability
Published 2026-01-13 · Analyzed
6.2EPSS 0.007
CVE-2024-38203
Windows Package Library Manager Information Disclosure Vulnerability
Published 2024-11-12 · Analyzed
6.2EPSS 0.007
CVE-2025-47980
Windows Imaging Component Information Disclosure Vulnerability
Published 2025-07-08 · Analyzed
6.2EPSS 0.006
CVE-2025-59258
Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
6.2EPSS 0.006
CVE-2025-29957
Windows Deployment Services Denial of Service Vulnerability
Published 2025-05-13 · Analyzed
6.2EPSS 0.006
CVE-2025-21278
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
Published 2025-01-14 · Analyzed
6.2EPSS 0.006
CVE-2026-50294
Windows Kernel Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.2EPSS 0.005
CVE-2023-35341
Microsoft DirectMusic Information Disclosure Vulnerability
Published 2023-07-11 · Modified
6.2EPSS 0.005
CVE-2023-21697
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Published 2023-02-14 · Modified
6.2EPSS 0.005
CVE-2026-25168
Windows Graphics Component Denial of Service Vulnerability
Published 2026-03-10 · Analyzed
6.2EPSS 0.005
CVE-2026-25169
Windows Graphics Component Denial of Service Vulnerability
Published 2026-03-10 · Analyzed
6.2EPSS 0.005
CVE-2026-40380
Windows Volume Manager Extension Driver Remote Code Execution Vulnerability
Published 2026-05-12 · Analyzed
6.2EPSS 0.004
CVE-2017-0055
Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability."
Published 2017-03-17 · Modified
6.1EPSS 0.164
CVE-2015-0006
The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."
Published 2015-01-13 · Modified
6.1EPSS 0.116
CVE-2016-7224
Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."
Published 2016-11-10 · Modified
6.11 PoCEPSS 0.041
CVE-2020-1220
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
Published 2020-06-09 · Modified
6.1EPSS 0.018
CVE-2016-7223
Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."
Published 2016-11-10 · Modified
6.1EPSS 0.014
CVE-2021-26886
User Profile Service Denial of Service Vulnerability
Published 2021-03-11 · Modified
6.1EPSS 0.011
CVE-2021-36961
Windows Installer Denial of Service Vulnerability
Published 2021-09-15 · Modified
6.1EPSS 0.011
CVE-2026-50453
Windows USB Audio Class Driver Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.1EPSS 0.005
CVE-2019-1470
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-12-10 · Modified
6.0EPSS 0.068
CVE-2025-21347
Windows Deployment Services Denial of Service Vulnerability
Published 2025-02-11 · Analyzed
6.0EPSS 0.007
CVE-2026-58638
Windows Boot Loader Security Feature Bypass Vulnerability
Published 2026-07-14 · Analyzed
6.0EPSS 0.002
CVE-2019-1166
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
Published 2019-10-10 · Modified
5.9EPSS 0.681
CVE-2019-1040
Windows NTLM Tampering Vulnerability
Published 2019-06-12 · Modified
5.9EPSS 0.480
CVE-2025-30394
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
Published 2025-05-13 · Analyzed
5.9EPSS 0.305
CVE-2017-0271
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.133
CVE-2017-0267
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.127
CVE-2017-8582
HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when the component improperly handles objects in memory, aka "Https.sys Information Disclosure Vulnerability".
Published 2017-07-11 · Modified
5.9EPSS 0.083
CVE-2017-0275
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.076
CVE-2017-0268
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.072
CVE-2017-0270
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0271, CVE-2017-0274, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.072
CVE-2017-0276
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0274, and CVE-2017-0275.
Published 2017-05-12 · Modified
5.9EPSS 0.072
CVE-2017-0274
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-0267, CVE-2017-0268, CVE-2017-0270, CVE-2017-0271, CVE-2017-0275, and CVE-2017-0276.
Published 2017-05-12 · Modified
5.9EPSS 0.070
CVE-2017-0269
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
Published 2017-05-12 · Modified
5.9EPSS 0.065
CVE-2017-0273
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.
Published 2017-05-12 · Modified
5.9EPSS 0.061
← Prev100 / 120Next →