VendorsMicrosoftwindows_server_2012any version
Vulnerabilities

Microsoft Windows Server 2012 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4720CVEs
CVE-2016-3341
The kernel-mode drivers in Transaction Manager in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Windows Transaction Manager Elevation of Privilege Vulnerability."
Published 2016-10-14 · Modified
9.3EPSS 0.066
CVE-2017-8578
Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8577, CVE-2017-8580, CVE-2017-8581, and CVE-2017-8467.
Published 2017-07-11 · Modified
9.3EPSS 0.065
CVE-2017-11847
Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to run arbitrary code in kernel mode, install programs, view, change or delete data, and create new accounts with full user rights due to improperly handing objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability".
Published 2017-11-15 · Modified
9.3EPSS 0.065
CVE-2017-0166
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege Vulnerability."
Published 2017-04-12 · Modified
9.3EPSS 0.064
CVE-2020-1013
Group Policy Elevation of Privilege Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.064
CVE-2020-0738
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
Published 2020-02-11 · Modified
9.3EPSS 0.061
CVE-2020-1113
A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'.
Published 2020-05-21 · Modified
9.3EPSS 0.061
CVE-2019-0906
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.057
CVE-2020-1408
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
9.3EPSS 0.056
CVE-2020-17042
Windows Print Spooler Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
9.3EPSS 0.051
CVE-2020-0922
Microsoft COM for Windows Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.049
CVE-2019-1183
Windows VBScript Engine Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.048
CVE-2016-4156
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.048
CVE-2019-0908
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.046
CVE-2019-1146
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.045
CVE-2019-1157
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.045
CVE-2020-16911
GDI+ Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
9.3EPSS 0.045
CVE-2019-1147
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.043
CVE-2019-1156
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.043
CVE-2019-1155
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.043
CVE-2020-1039
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.043
CVE-2019-0734
An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0936.
Published 2019-05-16 · Modified
9.3EPSS 0.042
CVE-2020-1558
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.042
CVE-2020-16924
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
9.3EPSS 0.041
CVE-2019-0907
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.041
CVE-2019-0905
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.041
CVE-2019-0974
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.041
CVE-2019-0904
Jet Database Engine Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.041
CVE-2020-1564
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.040
CVE-2020-1562
Microsoft Graphics Components Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.040
CVE-2016-4132
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.040
CVE-2020-1285
GDI+ Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.3EPSS 0.040
CVE-2020-1557
Jet Database Engine Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.039
CVE-2020-1153
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
9.3EPSS 0.038
CVE-2016-4131
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.038
CVE-2016-4133
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.038
CVE-2016-4134
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.038
CVE-2016-4139
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.038
CVE-2016-4140
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.038
CVE-2016-4141
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
Published 2016-06-16 · Modified
9.3EPSS 0.038
← Prev13 / 118Next →