CVE Vulnerabilities for "product:windows_server_2012"

Showing 1-10 of 3,981 CVEs (filtered from 316,407 total)

Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.

HIGH 8.8
EPSS 0.1%
10/14/2025
2025
CVE-2025-59287
⚠️🧬

Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

CRITICAL 9.8
EPSS 9.4%
10/14/2025
2025

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.

HIGH 7
EPSS 0.1%
10/14/2025
2025

Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.

LOW 3.1
EPSS 0.0%
10/14/2025
2025

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.1%
10/14/2025
2025

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.1%
10/14/2025
2025

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.1%
10/14/2025
2025

Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.

MEDIUM 6.5
EPSS 0.2%
10/14/2025
2025

Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.

MEDIUM 6.2
EPSS 0.1%
10/14/2025
2025

Improper access control in Microsoft Windows Search Component allows an authorized attacker to deny service locally.

MEDIUM 5.5
EPSS 0.0%
10/14/2025
2025
Page 1 of 2