VendorsMicrosoftwindows_server_2012any version
Vulnerabilities

Microsoft Windows Server 2012 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4710CVEs
CVE-2019-1384
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
Published 2019-11-12 · Modified
9.9EPSS 0.076
CVE-2019-1365
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.
Published 2019-10-10 · Modified
9.9EPSS 0.044
CVE-2020-1112
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
Published 2020-05-21 · Modified
9.9EPSS 0.033
CVE-2026-57092
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
9.9EPSS 0.009
CVE-2013-2251
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
Published 2013-07-18 · Analyzed
9.8KEV2 PoCEPSS 1.000
CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
9.8KEVEPSS 1.000
CVE-2023-21554
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
9.8EPSS 0.955
CVE-2023-24941
Windows Network File System Remote Code Execution Vulnerability
Published 2023-05-09 · Modified
9.8EPSS 0.947
CVE-2024-38077
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
9.8EPSS 0.841
CVE-2025-21298
Windows OLE Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
9.8EPSS 0.809
CVE-2022-34721
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
9.8EPSS 0.789
CVE-2022-26937
Windows Network File System Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
9.8EPSS 0.760
CVE-2024-49112
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
9.8EPSS 0.719
CVE-2024-38063
Windows TCP/IP Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
9.8EPSS 0.706
CVE-2019-0626
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-03-06 · Modified
9.8EPSS 0.686
CVE-2022-34718
Windows TCP/IP Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
9.8EPSS 0.544
CVE-2019-0785
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-07-15 · Modified
9.8EPSS 0.496
CVE-2021-34481
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
9.8EPSS 0.477
CVE-2024-30080
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2024-06-11 · Modified
9.8EPSS 0.431
CVE-2022-24497
Windows Network File System Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.8EPSS 0.346
CVE-2022-24491
Windows Network File System Remote Code Execution Vulnerability
Published 2022-04-15 · Modified
9.8EPSS 0.335
CVE-2025-47981
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
9.8EPSS 0.326
CVE-2019-0725
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
Published 2019-05-16 · Modified
9.8EPSS 0.282
CVE-2023-21690
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.275
CVE-2017-8686
The Windows Server DHCP service in Windows Server 2012 Gold and R2, and Windows Server 2016 allows an attacker to either run arbitrary code on the DHCP failover server or cause the DHCP service to become nonresponsive, due to a memory corruption vulnerability in the Windows Server DHCP service, aka "Windows DHCP Server Remote Code Execution Vulnerability".
Published 2017-09-13 · Modified
9.8EPSS 0.275
CVE-2023-21689
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.265
CVE-2021-24074
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.257
CVE-2021-24094
Windows TCP/IP Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.221
CVE-2023-21692
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.212
CVE-2025-55234
Windows SMB Elevation of Privilege Vulnerability
Published 2025-09-09 · Modified
9.8EPSS 0.201
CVE-2023-36397
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.175
CVE-2021-26877
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.8EPSS 0.165
CVE-2023-36049
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Published 2023-11-14 · Modified
9.8EPSS 0.125
CVE-2021-24078
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.119
CVE-2021-26432
Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.8EPSS 0.113
CVE-2024-43639
Windows KDC Proxy Remote Code Execution Vulnerability
Published 2024-11-12 · Analyzed
9.8EPSS 0.089
CVE-2025-53766
GDI+ Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
9.8EPSS 0.080
CVE-2021-36936
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-08-12 · Modified
9.8EPSS 0.074
CVE-2021-26893
Windows DNS Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
9.8EPSS 0.070
CVE-2019-1212
Windows DHCP Server Denial of Service Vulnerability
Published 2019-08-14 · Modified
9.8EPSS 0.067
← Prev2 / 118Next →