Known vulnerabilities in Windows Server 2012 Gold - page 16

Vendor: Microsoft
Version: 2012 Gold
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 906
Public exploits: 21
Known exploited (KEV): 26
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2012 Gold Windows Server 2012 Gold is affected by 906 vulnerabilities: 7 critical, 175 high, 142 medium, 581 low Critical High Medium Low

Vulnerabilities (906)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122554 - Untrusted Pointer Dereference
CVE-2026-21232
CWE-822 Low
No
No
2012 R2 6.3.9600.23022, 2022 23H2 10.0.25398.2149, 2025 10.0.26100.32313, 2025 10.0.26100.32370 10.02.2026 SB2026021065
#VU122553 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-21240
CWE-367 Low
No
No
2012 R2 6.3.9600.23022, 2019 10.0.17763.8389, 2022 23H2 10.0.25398.2149, 2022 10.0.20348.4711, 2022 10.0.20348.4773, 2025 10.0.26100.32313, 2025 10.0.26100.32370 10.02.2026 SB2026021065
#VU122552 - Type confusion
CVE-2026-21519
CWE-843 High
No
Exploited
2012 R2 6.3.9600.23022, 2016 10.0.14393.8868, 2019 10.0.17763.8389, 2022 23H2 10.0.25398.2149, 2022 10.0.20348.4711, 2022 10.0.20348.4773, 2025 10.0.26100.32313, 2025 10.0.26100.32370 10.02.2026 SB2026021064
#VU122551 - Untrusted Pointer Dereference
CVE-2026-21250
CWE-822 Low
No
No
2012 R2 6.3.9600.23022, 2022 23H2 10.0.25398.2149, 2025 10.0.26100.32313, 2025 10.0.26100.32370 10.02.2026 SB2026021065
#VU122549 - Use After Free
CVE-2026-21251
CWE-416 Low
No
No
2012 R2 6.3.9600.23022, 2016 10.0.14393.8868, 2019 10.0.17763.8389, 2022 23H2 10.0.25398.2149, 2022 10.0.20348.4711, 2022 10.0.20348.4773, 2025 10.0.26100.32313, 2025 10.0.26100.32370 10.02.2026 SB2026021059
#VU122543 - Information Exposure Through Log Files
CVE-2026-21222
CWE-532 Medium
No
No
2012 R2 6.3.9600.23022, 2016 10.0.14393.8868, 2019 10.0.17763.8389, 2022 23H2 10.0.25398.2149, 2022 10.0.20348.4711, 2022 10.0.20348.4773, 2025 10.0.26100.32313, 2025 10.0.26100.32370 10.02.2026 SB2026021054
#VU122539 - Heap-based Buffer Overflow
CVE-2026-21245
CWE-122 Low
No
No
2012 R2 6.3.9600.23022, 2025 10.0.26100.32313, 2025 10.0.26100.32370 10.02.2026 SB2026021054
#VU121449 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-20809
CWE-367 Low
No
No
2012 R2 6.3.9600.22968, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011499
#VU119474 - Integer underflow
CVE-2025-62567
CWE-191 Medium
No
No
2008 6.0.6003.23666, 2012 R2 6.3.9600.22920, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120978
#VU118304 - Out-of-bounds read
CVE-2025-59513
CWE-125 Low
No
No
2008 R2 6.1.7601.28021, 2008 6.0.6003.23624, 2012 R2 6.3.9600.22869, 2016 10.0.14393.8594, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111170
#VU118301 - External Control of File Name or Path
CVE-2025-59511
CWE-73 Low
No
No
2012 R2 6.3.9600.22869, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111167
#VU118300 - Insertion of Sensitive Information Into Sent Data
CVE-2025-59509
CWE-201 Low
No
No
2012 R2 6.3.9600.22869, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111166
#VU118299 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-59508
CWE-362 Low
No
No
2012 R2 6.3.9600.22869, 2016 10.0.14393.8594, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111166
#VU118298 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-59507
CWE-362 Low
No
No
2012 R2 6.3.9600.22869, 2016 10.0.14393.8594, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111165
#VU118281 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-59510
CWE-59 Low
No
No
2012 R2 6.3.9600.22869, 2016 10.0.14393.8594, 2019 10.0.17763.8027, 2022 23H2 10.0.25398.1965, 2022 10.0.20348.4346, 2022 10.0.20348.4405, 2025 10.0.26100.7092, 2025 10.0.26100.7171 11.11.2025 SB2025111152
#VU117285 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2025-55696
CWE-367 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB20251015133
#VU117278 - Cleartext Transmission of Sensitive Information
CVE-2025-53139
CWE-319 Low
No
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 15.10.2025 SB20251015126
#VU117235 - Exposure of sensitive information to an unauthorized actor
CVE-2025-59284
CWE-200 Medium
Public exploit available
No
2012 R2 6.3.9600.22824, 2025 10.0.26100.6899 15.10.2025 SB2025101592
#VU117233 - Use of a Key Past its Expiration Date
CVE-2025-48813
CWE-324 Low
No
No
2012 R2 6.3.9600.22824, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101590
#VU117230 - Buffer over-read
CVE-2025-59192
CWE-126 Low
No
No
2012 R2 6.3.9600.22824, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 15.10.2025 SB2025101587


Showing elements 301 - 320 out of 906