VendorsMicrosoftwindows_server_2012any version
Vulnerabilities

Microsoft Windows Server 2012 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4774CVEs
CVE-2026-69317
Windows Remote Desktop Client Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.009
CVE-2026-68874
Windows Program Compatibility Assistant Service Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.009
CVE-2026-69552
Windows Print Spooler Components Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.009
CVE-2026-69572
Windows SMB Client Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.009
CVE-2026-69723
Windows Kernel Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.009
CVE-2026-69569
Windows Print Spooler Components Denial of Service Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.009
CVE-2026-69372
Windows Network File System Denial of Service Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.009
CVE-2022-30223
Windows Hyper-V Information Disclosure Vulnerability
Published 2022-07-12 · Modified
5.7EPSS 0.008
CVE-2025-55248
.NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
5.7EPSS 0.007
CVE-2025-29974
Windows Kernel Information Disclosure Vulnerability
Published 2025-05-13 · Analyzed
5.7EPSS 0.007
CVE-2026-50485
Windows Hyper-V Denial of Service Vulnerability
Published 2026-07-14 · Analyzed
5.7EPSS 0.007
CVE-2026-69679
Windows DHCP Server Denial of Service Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.006
CVE-2026-69637
Windows DHCP Server Denial of Service Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.006
CVE-2026-69416
Windows DHCP Server Denial of Service Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.006
CVE-2026-69405
Windows DHCP Server Denial of Service Vulnerability
Published 2026-09-08 · Analyzed
5.7EPSS 0.006
CVE-2025-49722
Windows Print Spooler Denial of Service Vulnerability
Published 2025-07-08 · Analyzed
5.7EPSS 0.006
CVE-2022-22711
Windows BitLocker Information Disclosure Vulnerability
Published 2022-07-12 · Modified
5.7EPSS 0.005
CVE-2019-1125
Windows Kernel Information Disclosure Vulnerability
Published 2019-09-03 · Modified
5.61 PoCEPSS 0.045
CVE-2015-0095
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service (NULL pointer dereference and blue screen), or obtain sensitive information from kernel memory and possibly bypass the ASLR protection mechanism, via a crafted application, aka "Microsoft Windows Kernel Memory Disclosure Vulnerability."
Published 2015-03-11 · Modified
5.6EPSS 0.027
CVE-2018-0888
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how guest operating system input is validated, aka "Hyper-V Information Disclosure Vulnerability".
Published 2018-03-14 · Modified
5.6EPSS 0.014
CVE-2023-32020
Windows DNS Spoofing Vulnerability
Published 2023-06-13 · Modified
5.6EPSS 0.007
CVE-2025-21336
Windows Cryptographic Information Disclosure Vulnerability
Published 2025-01-14 · Modified
5.6EPSS 0.006
CVE-2026-69832
Win32k Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.6EPSS 0.004
CVE-2017-0038
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.
Published 2017-02-20 · Modified
5.51 PoCEPSS 0.821
CVE-2016-3209
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; Live Meeting 2007 Console; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4.5.2, and 4.6; and Silverlight 5 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "True Type Font Parsing Information Disclosure Vulnerability."
Published 2016-10-14 · Modified
5.51 PoCEPSS 0.537
CVE-2016-3371
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
Published 2016-09-14 · Modified
5.51 PoCEPSS 0.401
CVE-2022-37985
Windows Graphics Component Information Disclosure Vulnerability
Published 2022-10-11 · Modified
5.5EPSS 0.386
CVE-2016-3215
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3201.
Published 2016-06-16 · Modified
5.5EPSS 0.336
CVE-2016-3262
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "GDI+ Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3263.
Published 2016-10-14 · Modified
5.5EPSS 0.320
CVE-2016-3263
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "GDI+ Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3262.
Published 2016-10-14 · Modified
5.5EPSS 0.320
CVE-2017-8683
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8682.
Published 2017-09-13 · Modified
5.51 PoCEPSS 0.226
CVE-2017-11816
The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, aka "Windows GDI Information Disclosure Vulnerability".
Published 2017-10-13 · Modified
5.5EPSS 0.200
CVE-2020-1599
Windows Spoofing Vulnerability
Published 2020-11-11 · Modified
5.5EPSS 0.191
CVE-2018-8472
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-10-10 · Modified
5.5EPSS 0.189
CVE-2016-3373
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly implement registry access control, which allows local users to obtain sensitive account information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."
Published 2016-09-14 · Modified
5.51 PoCEPSS 0.175
CVE-2017-0060
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI+ Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0060 and CVE-2017-0062.
Published 2017-03-17 · Modified
5.51 PoCEPSS 0.159
CVE-2017-0211
An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation of Privilege Vulnerability."
Published 2017-04-12 · Modified
5.51 PoCEPSS 0.141
CVE-2019-0948
Windows Event Viewer Information Disclosure Vulnerability
Published 2019-06-12 · Modified
5.51 PoCEPSS 0.127
CVE-2016-0070
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability."
Published 2016-10-14 · Modified
5.51 PoCEPSS 0.115
CVE-2023-20588
Speculative Leaks
Published 2023-08-08 · Modified
5.5EPSS 0.112
← Prev102 / 120Next →