VendorsMicrosoftwindows_server_2012any version
Vulnerabilities

Microsoft Windows Server 2012 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4774CVEs
CVE-2017-0169
An information disclosure vulnerability exists when Windows Hyper-V running on a Windows 8.1, Windows Server 2012. or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0168.
Published 2017-04-12 · Modified
5.4EPSS 0.016
CVE-2017-0099
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0076, and CVE-2017-0097.
Published 2017-03-17 · Modified
5.4EPSS 0.014
CVE-2017-0097
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0074, CVE-2017-0076, and CVE-2017-0099.
Published 2017-03-17 · Modified
5.4EPSS 0.014
CVE-2017-0074
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of service via a crafted application, aka "Hyper-V Denial of Service Vulnerability." This vulnerability is different from those described in CVE-2017-0098, CVE-2017-0076, CVE-2017-0097, and CVE-2017-0099.
Published 2017-03-17 · Modified
5.4EPSS 0.014
CVE-2025-29956
Windows SMB Information Disclosure Vulnerability
Published 2025-05-13 · Analyzed
5.4EPSS 0.010
CVE-2020-1596
TLS Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.4EPSS 0.009
CVE-2025-47160
Windows Shortcut Files Security Feature Bypass Vulnerability
Published 2025-06-10 · Analyzed
5.4EPSS 0.008
CVE-2026-35423
Windows 11 Telnet Client Information Disclosure Vulnerability
Published 2026-05-12 · Analyzed
5.4EPSS 0.007
CVE-2017-11906
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11887 and CVE-2017-11919.
Published 2017-12-12 · Modified
5.31 PoCEPSS 0.251
CVE-2023-38152
DHCP Server Service Information Disclosure Vulnerability
Published 2023-09-12 · Modified
5.3EPSS 0.240
CVE-2016-0050
Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage) via crafted requests, aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."
Published 2016-02-10 · Modified
5.3EPSS 0.179
CVE-2016-3299
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to hijack network traffic or bypass intended Enhanced Protected Mode (EPM) or application container protection mechanisms, and consequently render untrusted content in a browser, by leveraging how NetBIOS validates responses, aka "NetBIOS Spoofing Vulnerability."
Published 2016-08-09 · Modified
5.3EPSS 0.136
CVE-2017-11815
The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an information disclosure vulnerability in the way that it handles certain requests, aka "Windows SMB Information Disclosure Vulnerability".
Published 2017-10-13 · Modified
5.3EPSS 0.133
CVE-2017-11834
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11791.
Published 2017-11-15 · Modified
5.3EPSS 0.127
CVE-2017-8695
Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an attacker to obtain information to further compromise a user's system via a specially crafted document or an untrusted webpage, aka "Graphics Component Information Disclosure Vulnerability."
Published 2017-09-13 · Modified
5.3EPSS 0.096
CVE-2018-1000
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0987, CVE-2018-0989.
Published 2018-04-12 · Modified
5.3EPSS 0.075
CVE-2017-11887
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how Internet Explorer handle objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11906 and CVE-2017-11919.
Published 2017-12-12 · Modified
5.3EPSS 0.064
CVE-2018-0981
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0987, CVE-2018-0989, CVE-2018-1000.
Published 2018-04-12 · Modified
5.3EPSS 0.064
CVE-2018-0976
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-04-12 · Modified
5.3EPSS 0.047
CVE-2020-1315
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
Published 2020-06-09 · Modified
5.3EPSS 0.038
CVE-2017-8713
The Windows Hyper-V component on Microsoft Windows Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8707, CVE-2017-8711, CVE-2017-8712, and CVE-2017-8706.
Published 2017-09-13 · Modified
5.3EPSS 0.035
CVE-2017-0043
Active Directory Federation Services in Microsoft Windows 10 1607, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and Windows Server 2016 allows local users to obtain sensitive information via a crafted application, aka "Microsoft Active Directory Federation Services Information Disclosure Vulnerability."
Published 2017-03-17 · Modified
5.3EPSS 0.021
CVE-2023-36012
DHCP Server Service Information Disclosure Vulnerability
Published 2023-12-12 · Modified
5.3EPSS 0.020
CVE-2022-30154
Microsoft File Server Shadow Copy Agent Service (RVSS) Elevation of Privilege Vulnerability
Published 2022-06-15 · Modified
5.3EPSS 0.017
CVE-2023-36801
DHCP Server Service Information Disclosure Vulnerability
Published 2023-09-12 · Modified
5.3EPSS 0.016
CVE-2023-21525
Remote Procedure Call Runtime Denial of Service Vulnerability
Published 2023-01-10 · Modified
5.3EPSS 0.015
CVE-2024-21313
Windows TCP/IP Information Disclosure Vulnerability
Published 2024-01-09 · Modified
5.3EPSS 0.015
CVE-2023-21682
Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
Published 2023-01-10 · Modified
5.3EPSS 0.014
CVE-2023-21729
Remote Procedure Call Runtime Information Disclosure Vulnerability
Published 2023-04-11 · Modified
5.3EPSS 0.013
CVE-2023-29355
DHCP Server Service Information Disclosure Vulnerability
Published 2023-06-13 · Modified
5.3EPSS 0.013
CVE-2023-21699
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Published 2023-02-14 · Modified
5.3EPSS 0.011
CVE-2026-25185
Windows Shell Link Processing Spoofing Vulnerability
Published 2026-03-10 · Analyzed
5.3EPSS 0.010
CVE-2026-20927
Windows SMB Server Denial of Service Vulnerability
Published 2026-01-13 · Analyzed
5.3EPSS 0.009
CVE-2024-35270
Windows iSCSI Service Denial of Service Vulnerability
Published 2024-07-09 · Modified
5.3EPSS 0.009
CVE-2026-78446
Windows Distributed File System (DFS) Denial of Service Vulnerability
Published 2026-09-08 · Analyzed
5.3EPSS 0.008
CVE-2026-42914
Windows Kerberos Denial of Service Vulnerability
Published 2026-06-09 · Modified
5.3EPSS 0.008
CVE-2026-45655
Windows BitLocker Security Feature Bypass Vulnerability
Published 2026-06-09 · Analyzed
5.3EPSS 0.005
CVE-2014-0296
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly encrypt sessions, which makes it easier for man-in-the-middle attackers to obtain sensitive information by sniffing the network or modify session content by sending crafted RDP packets, aka "RDP MAC Vulnerability."
Published 2014-06-11 · Modified
5.1EPSS 0.057
CVE-2014-0255
Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."
Published 2014-05-14 · Modified
5.0EPSS 0.418
CVE-2014-0256
Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."
Published 2014-05-14 · Modified
5.0EPSS 0.418
← Prev113 / 120Next →