VendorsMicrosoftwindows_server_2012any version
Vulnerabilities

Microsoft Windows Server 2012 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4749CVEs
CVE-2021-42278
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2021-11-10 · Analyzed
7.5KEVEPSS 0.733
CVE-2023-36606
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.672
CVE-2021-36942
Windows LSA Spoofing Vulnerability
Published 2021-08-12 · Analyzed
7.5KEVEPSS 0.660
CVE-2024-26212
DHCP Server Service Denial of Service Vulnerability
Published 2024-04-09 · Analyzed
7.5EPSS 0.626
CVE-2021-24086
Windows TCP/IP Denial of Service Vulnerability
Published 2021-02-25 · Modified
7.5EPSS 0.590
CVE-2025-21285
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2025-01-14 · Analyzed
7.5EPSS 0.557
CVE-2022-35748
HTTP.sys Denial of Service Vulnerability
Published 2023-05-31 · Modified
7.5EPSS 0.472
CVE-2023-21818
Windows Secure Channel Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.432
CVE-2025-21277
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2025-01-14 · Analyzed
7.5EPSS 0.386
CVE-2022-34689
Windows CryptoAPI Spoofing Vulnerability
Published 2022-10-11 · Modified
7.5EPSS 0.379
CVE-2024-38071
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Published 2024-07-09 · Modified
7.5EPSS 0.359
CVE-2022-22025
Windows Internet Information Services Cachuri Module Denial of Service Vulnerability
Published 2022-07-12 · Modified
7.5EPSS 0.327
CVE-2025-30397
Scripting Engine Memory Corruption Vulnerability
Published 2025-05-13 · Analyzed
7.5KEV1 PoCEPSS 0.268
CVE-2025-53722
Windows Remote Desktop Services Denial of Service Vulnerability
Published 2025-08-12 · Analyzed
7.5EPSS 0.223
CVE-2016-3237
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via vectors related to a fallback to NTLM authentication during a domain account password change, aka "Kerberos Security Feature Bypass Vulnerability."
Published 2016-08-09 · Modified
7.51 PoCEPSS 0.172
CVE-2025-47984
Windows GDI Information Disclosure Vulnerability
Published 2025-07-08 · Analyzed
7.5EPSS 0.169
CVE-2020-16896
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2020-10-16 · Modified
7.5EPSS 0.126
CVE-2014-0316
Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (memory consumption) and bypass the ASLR protection mechanism via a crafted client that sends messages with an invalid data view, aka "LRPC ASLR Bypass Vulnerability."
Published 2014-08-12 · Modified
7.5EPSS 0.115
CVE-2023-38162
DHCP Server Service Denial of Service Vulnerability
Published 2023-09-12 · Modified
7.5EPSS 0.107
CVE-2019-1453
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
Published 2019-12-10 · Modified
7.5EPSS 0.099
CVE-2019-0545
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.
Published 2019-01-08 · Modified
7.5EPSS 0.096
CVE-2020-1374
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
7.5EPSS 0.091
CVE-2018-8360
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.
Published 2018-08-15 · Modified
7.5EPSS 0.090
CVE-2018-0764
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765.
Published 2018-01-10 · Modified
7.5EPSS 0.089
CVE-2017-11772
The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure when it fails to properly handle objects in memory, aka "Microsoft Search Information Disclosure Vulnerability".
Published 2017-10-13 · Modified
7.5EPSS 0.083
CVE-2018-0765
A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, .NET Core 2.0, Microsoft .NET Framework 4.7.2.
Published 2018-05-09 · Modified
7.5EPSS 0.083
CVE-2017-11788
Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remotely send specially crafted messages that could cause a denial of service against the system due to improperly handing objects in memory, aka "Windows Search Denial of Service Vulnerability".
Published 2017-11-15 · Modified
7.5EPSS 0.079
CVE-2019-0688
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP Information Disclosure Vulnerability'.
Published 2019-04-09 · Modified
7.5EPSS 0.079
CVE-2019-1083
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.078
CVE-2017-11846
ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11836, CVE-2017-11837, CVE-2017-11838, CVE-2017-11839, CVE-2017-11840, CVE-2017-11841, CVE-2017-11843, CVE-2017-11858, CVE-2017-11859, CVE-2017-11861, CVE-2017-11862, CVE-2017-11866, CVE-2017-11869, CVE-2017-11870, CVE-2017-11871, and CVE-2017-11873.
Published 2017-11-15 · Modified
7.5EPSS 0.077
CVE-2021-26896
Windows DNS Server Denial of Service Vulnerability
Published 2021-03-11 · Modified
7.5EPSS 0.074
CVE-2018-17612
Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for several years, even if the HeadSetup product is uninstalled. NOTE: a vulnerability-assessment approach must check all Windows systems for CA certificates with a CN of 127.0.0.1 or SennComRootCA, and determine whether those certificates are unwanted.
Published 2018-11-09 · Modified
7.5EPSS 0.067
CVE-2021-31974
Server for NFS Denial of Service Vulnerability
Published 2021-06-08 · Modified
7.5EPSS 0.067
CVE-2020-0611
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
Published 2020-01-14 · Modified
7.5EPSS 0.067
CVE-2016-7247
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow physically proximate attackers to bypass the Secure Boot protection mechanism via a crafted boot policy, aka "Secure Boot Component Vulnerability."
Published 2016-11-10 · Modified
7.5EPSS 0.067
CVE-2021-43893
Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
Published 2021-12-15 · Modified
7.5EPSS 0.066
CVE-2023-28227
Windows Bluetooth Driver Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
7.5EPSS 0.066
CVE-2021-27063
Windows DNS Server Denial of Service Vulnerability
Published 2021-03-11 · Modified
7.5EPSS 0.063
CVE-2020-1108
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
Published 2020-05-21 · Modified
7.5EPSS 0.063
CVE-2021-28439
Windows TCP/IP Driver Denial of Service Vulnerability
Published 2021-04-13 · Modified
7.5EPSS 0.061
← Prev68 / 119Next →