VendorsMicrosoftwindows_server_2012any version
Vulnerabilities

Microsoft Windows Server 2012 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4732CVEs
CVE-2023-28236
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-04-11 · Modified
7.8EPSS 0.003
CVE-2023-35362
Windows Clip Service Elevation of Privilege Vulnerability
Published 2023-07-11 · Modified
7.8EPSS 0.003
CVE-2025-54895
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Elevation of Privilege Vulnerability
Published 2025-09-09 · Analyzed
7.8EPSS 0.003
CVE-2026-57093
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2026-54989
Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2026-50359
Microsoft XML Core Services Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2026-50490
Windows Installer Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2026-50390
Windows Kernel Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2026-50491
Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2026-50476
Windows Network Connections Service Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2026-50688
Windows Win32k Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2025-59275
Windows Authentication Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.8EPSS 0.003
CVE-2025-59278
Windows Authentication Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.8EPSS 0.003
CVE-2023-35340
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Published 2023-07-11 · Modified
7.8EPSS 0.003
CVE-2025-58714
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.8EPSS 0.003
CVE-2026-72927
Winsock Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
7.8EPSS 0.002
CVE-2026-50667
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-50321
Windows USB Driver Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-34334
Windows TCP/IP Elevation of Privilege Vulnerability
Published 2026-05-12 · Analyzed
7.8EPSS 0.002
CVE-2026-34351
Windows TCP/IP Elevation of Privilege Vulnerability
Published 2026-05-12 · Analyzed
7.8EPSS 0.002
CVE-2026-50673
Windows Kernel Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.002
CVE-2026-26168
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
7.8EPSS 0.002
CVE-2026-81355
Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
7.8EPSS 0.002
CVE-2020-16997
Remote Desktop Protocol Server Information Disclosure Vulnerability
Published 2020-11-11 · Modified
7.7EPSS 0.040
CVE-2021-34500
Windows Kernel Memory Information Disclosure Vulnerability
Published 2021-07-14 · Modified
7.7EPSS 0.026
CVE-2021-40463
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published 2021-10-13 · Modified
7.7EPSS 0.026
CVE-2025-29833
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
Published 2025-05-13 · Analyzed
7.7EPSS 0.004
CVE-2026-27913
Windows BitLocker Security Feature Bypass Vulnerability
Published 2026-04-14 · Analyzed
7.7EPSS 0.004
CVE-2016-0189
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
Published 2016-05-11 · Analyzed
7.6KEV1 PoCEPSS 0.941
CVE-2018-8174
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-05-09 · Analyzed
7.6KEV1 PoCEPSS 0.883
CVE-2020-0674
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
Published 2020-02-11 · Analyzed
7.6KEV2 PoCEPSS 0.869
CVE-2018-0886
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, version 1709 allows a remote code execution vulnerability due to how CredSSP validates request during the authentication process, aka "CredSSP Remote Code Execution Vulnerability".
Published 2018-03-14 · Modified
7.61 PoCEPSS 0.820
CVE-2019-0752
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.
Published 2019-04-09 · Analyzed
7.6KEV1 PoCEPSS 0.816
CVE-2019-1429
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
Published 2019-11-12 · Analyzed
7.6KEV1 PoCEPSS 0.773
CVE-2017-8636
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
Published 2017-08-08 · Modified
7.64 PoCEPSS 0.721
CVE-2017-8641
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.
Published 2017-08-08 · Modified
7.61 PoCEPSS 0.716
CVE-2018-8631
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
Published 2018-12-12 · Modified
7.61 PoCEPSS 0.685
CVE-2018-8353
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.
Published 2018-08-15 · Modified
7.61 PoCEPSS 0.677
CVE-2018-8145
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177.
Published 2018-05-09 · Modified
7.61 PoCEPSS 0.672
CVE-2017-11907
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how Internet Explorer handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11886, CVE-2017-11889, CVE-2017-11890, CVE-2017-11893, CVE-2017-11894, CVE-2017-11895, CVE-2017-11901, CVE-2017-11903, CVE-2017-11905, CVE-2017-11905, CVE-2017-11908, CVE-2017-11909, CVE-2017-11910, CVE-2017-11911, CVE-2017-11912, CVE-2017-11913, CVE-2017-11914, CVE-2017-11916, CVE-2017-11918, and CVE-2017-11930.
Published 2017-12-12 · Modified
7.61 PoCEPSS 0.647
← Prev63 / 119Next →