windows_server_2012 vulnerabilities
CVEs whose affected-version data names the windows_server_2012 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
868 CVEsRSS
CVE-2026-77886High· 7.5Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77505High· 8.1Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.
CVE-2026-77504High· 8.8Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-77503High· 8.4Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
CVE-2026-77502High· 7.5Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77501High· 7.5Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77499High· 7.5Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77498High· 7.5Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77495High· 8.8Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-77494High· 7.5Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
CVE-2026-77493Critical· 9.8Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2026-77492Medium· 5.5Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.
CVE-2026-77491Medium· 5.5Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.
CVE-2026-73025Critical· 9.8Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-73024High· 7.8Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-73023High· 8.8Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-73019Medium· 4.3Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-73018High· 8.8Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
CVE-2026-73016High· 8.8Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2026-73013High· 8.8Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
CVE-2026-73012High· 8.8Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
CVE-2026-73009Critical· 9.8Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
CVE-2026-72987High· 8.1Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-72986High· 8.8Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
CVE-2026-72985Medium· 6.8Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
Heap-based buffer overflow in Windows Volume Shadow Copy allows an unauthorized attacker to elevate privileges with a physical attack.
CVE-2026-72983Critical· 9.8Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
CVE-2026-72982Critical· 9.8Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
CVE-2026-72981High· 8.1Use after free in IP Helper allows an unauthorized attacker to execute code over a network.
Use after free in IP Helper allows an unauthorized attacker to execute code over a network.
CVE-2026-72979Critical· 9.8Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-72978Medium· 5.9Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.