Known vulnerabilities in Windows Server 2012 Gold

Vendor: Microsoft
Version: 2012 Gold
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 906
Public exploits: 21
Known exploited (KEV): 26
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2012 Gold Windows Server 2012 Gold is affected by 906 vulnerabilities: 7 critical, 175 high, 142 medium, 581 low Critical High Medium Low

Vulnerabilities (906)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137969 - Allocation of Resources Without Limits or Throttling
CVE-2026-49788
CWE-770 Medium
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137968 - Allocation of Resources Without Limits or Throttling
CVE-2026-49787
CWE-770 Medium
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137967 - Improper Access Control
CVE-2026-49783
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137966 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-49183
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137961 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-44800
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137957 - Protection Mechanism Failure
CVE-2026-34348
CWE-693 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137955 - Exposure of sensitive information to an unauthorized actor
CVE-2026-34328
CWE-200 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137953 - Command injection
CVE-2026-58635
CWE-77 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137948 - Use After Free
CVE-2026-54127
CWE-416 Low
No
No
2012 R2 6.3.9600.23291, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137946 - Missing Required Cryptographic Step
CVE-2026-55144
CWE-325 Low
No
No
2012 R2 6.3.9600.23291, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137941 - Use After Free
CVE-2026-54114
CWE-416 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137939 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-54112
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137938 - Improper Certificate Validation
CVE-2026-55001
CWE-295 Low
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137937 - Heap-based Buffer Overflow
CVE-2026-54986
CWE-122 Low
No
No
2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137935 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-54111
CWE-362 Low
No
No
2012 R2 6.3.9600.23291, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137934 - Heap-based Buffer Overflow
CVE-2026-54990
CWE-122 High
No
No
2012 R2 6.3.9600.23291, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137932 - Use After Free
CVE-2026-54129
CWE-416 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137931 - Missing Authentication for Critical Function
CVE-2026-49174
CWE-306 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137930 - Improper Access Control
CVE-2026-49170
CWE-284 Low
No
No
2012 R2 6.3.9600.23291, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158 17.07.2026 SB2026071705
#VU137929 - Use After Free
CVE-2026-49169
CWE-416 Medium
No
No
2012 R2 6.3.9600.23291, 2025 10.0.26100.33158 17.07.2026 SB2026071705


Showing elements 1 - 20 out of 906