VendorsMicrosoftwindows_server_2012any version
Vulnerabilities

Microsoft Windows Server 2012 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4720CVEs
CVE-2020-1300
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses the vulnerability by correcting how Windows handles cabinet files., aka 'Windows Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.594
CVE-2024-43461
Windows MSHTML Platform Spoofing Vulnerability
Published 2024-09-10 · Analyzed
8.8KEVEPSS 0.545
CVE-2025-53778
Windows NTLM Elevation of Privilege Vulnerability
Published 2025-08-12 · Modified
8.8EPSS 0.476
CVE-2014-4123
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.
Published 2014-10-15 · Analyzed
8.8KEVEPSS 0.471
CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
Published 2013-12-11 · Analyzed
8.8KEVEPSS 0.446
CVE-2020-1301
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.438
CVE-2022-24500
Windows SMB Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
8.8EPSS 0.380
CVE-2023-28231
DHCP Server Service Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
8.8EPSS 0.366
CVE-2021-34480
Scripting Engine Memory Corruption Vulnerability
Published 2021-08-12 · Modified
8.8EPSS 0.339
CVE-2024-38144
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Published 2024-08-13 · Analyzed
8.8EPSS 0.323
CVE-2020-0729
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
8.8EPSS 0.309
CVE-2017-0222
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
Published 2017-05-12 · Analyzed
8.8KEVEPSS 0.296
CVE-2017-0149
Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.
Published 2017-03-17 · Analyzed
8.8KEVEPSS 0.292
CVE-2014-2817
Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
Published 2014-08-12 · Analyzed
8.8KEVEPSS 0.263
CVE-2022-23285
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-03-09 · Modified
8.8EPSS 0.256
CVE-2023-36017
Windows Scripting Engine Memory Corruption Vulnerability
Published 2023-11-14 · Modified
8.8EPSS 0.253
CVE-2022-41128
Windows Scripting Languages Remote Code Execution Vulnerability
Published 2022-11-09 · Analyzed
8.8KEVEPSS 0.246
CVE-2026-21510
Windows Shell Security Feature Bypass Vulnerability
Published 2026-02-10 · Analyzed
8.8KEVEPSS 0.242
CVE-2020-1380
Scripting Engine Memory Corruption Vulnerability
Published 2020-08-17 · Analyzed
8.8KEVEPSS 0.242
CVE-2017-0210
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
Published 2017-04-12 · Analyzed
8.8KEVEPSS 0.223
CVE-2021-34535
Remote Desktop Client Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
8.8EPSS 0.217
CVE-2020-1436
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Windows Font Library Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
8.8EPSS 0.213
CVE-2025-54918
Windows NTLM Elevation of Privilege Vulnerability
Published 2025-09-09 · Analyzed
8.8EPSS 0.194
CVE-2025-21293
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
8.8EPSS 0.190
CVE-2022-21990
Remote Desktop Client Remote Code Execution Vulnerability
Published 2022-03-09 · Modified
8.8EPSS 0.188
CVE-2024-20674
Windows Kerberos Security Feature Bypass Vulnerability
Published 2024-01-09 · Modified
8.8EPSS 0.172
CVE-2017-11762
The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.
Published 2017-10-13 · Modified
8.8EPSS 0.171
CVE-2017-11763
The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.
Published 2017-10-13 · Modified
8.8EPSS 0.171
CVE-2024-38060
Windows Imaging Component Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
8.8EPSS 0.159
CVE-2018-8475
A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-09-13 · Modified
8.8EPSS 0.159
CVE-2026-21513
MSHTML Framework Security Feature Bypass Vulnerability
Published 2026-02-10 · Analyzed
8.8KEVEPSS 0.156
CVE-2018-8260
A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
8.8EPSS 0.155
CVE-2021-38666
Remote Desktop Client Remote Code Execution Vulnerability
Published 2021-11-10 · Modified
8.8EPSS 0.151
CVE-2015-2360
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Published 2015-06-10 · Analyzed
8.8KEVEPSS 0.148
CVE-2020-1281
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.145
CVE-2025-29962
Windows Media Remote Code Execution Vulnerability
Published 2025-05-13 · Analyzed
8.8EPSS 0.143
CVE-2024-43532
Remote Registry Service Elevation of Privilege Vulnerability
Published 2024-10-08 · Analyzed
8.8EPSS 0.120
CVE-2019-1419
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1456.
Published 2019-11-12 · Modified
8.8EPSS 0.116
CVE-2019-1113
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.
Published 2019-07-29 · Modified
8.8EPSS 0.100
CVE-2019-1456
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts, aka 'OpenType Font Parsing Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1419.
Published 2019-11-12 · Modified
8.8EPSS 0.097
← Prev16 / 118Next →