Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows Server 2012.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-62738MEDIUM | Windows Management Instrumentation Information Disclosure VulnerabilityOut-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.397% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65796MEDIUM | Windows iSCSI Target Service Denial of Service VulnerabilityHeap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. CWE-122Aug 11, 2026 | CVSS5.9v3.1 | EPSS0.645% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65798MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. CWE-197Aug 11, 2026 | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65799MEDIUM | Windows DNS Elevation of Privilege VulnerabilityInteger overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65797MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65794MEDIUM | Windows SMB Client Information Disclosure VulnerabilityBuffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. CWE-126Aug 11, 2026 | CVSS6.5v3.1 | EPSS0.666% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65791CRITICAL | Windows iSCSI Target Service Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CWE-122Aug 11, 2026 | CVSS9.8v3.1 | EPSS0.601% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65790HIGH | Windows Message Queuing Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65775HIGH | Windows Win32k Elevation of Privilege VulnerabilityUse after free in Windows Win32K allows an authorized attacker to elevate privileges locally. CWE-416Aug 11, 2026 | CVSS7.8v3.1 | EPSS2.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65774HIGH | Windows Installer Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65679HIGH | Windows iSCSI Target Service Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. CWE-122Aug 11, 2026 | CVSS8.1v3.1 | EPSS0.557% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62887MEDIUM | Windows NTFS Information Disclosure VulnerabilityOut-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.306% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62885HIGH | Windows Win32k Elevation of Privilege VulnerabilityHeap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. CWE-122Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62883MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.256% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62881MEDIUM | Windows DNS Elevation of Privilege VulnerabilityNumeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | CVSS6.7v3.1 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62880HIGH | Windows NTFS Elevation of Privilege VulnerabilityOut-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally. CWE-125Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62822HIGH | Windows GDI+ Remote Code Execution VulnerabilityInteger overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | CVSS8.8v3.1 | EPSS0.633% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62824HIGH | Remote Desktop Client Remote Code Execution VulnerabilityStack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. CWE-121Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.626% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62823HIGH | Windows DHCP Server Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. CWE-122Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.555% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62814MEDIUM | Windows DHCP Server Information Disclosure VulnerabilityInteger underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. | CVSS6.5v3.1 | EPSS0.549% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62807HIGH | Windows DHCP Server Elevation of Privilege VulnerabilityImproper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. CWE-59Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62803HIGH | Windows DHCP Server Elevation of Privilege VulnerabilityImproper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. CWE-59Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62793MEDIUM | Windows NTFS Information Disclosure VulnerabilityBuffer over-read in Windows NTFS allows an authorized attacker to disclose information locally. CWE-126Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62790HIGH | Windows SMBv3 Server Remote Code Execution VulnerabilityHeap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. CWE-122Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.663% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62786MEDIUM | Win32k Information Disclosure VulnerabilityOut-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally. CWE-125Aug 11, 2026 | CVSS5.5v3.1 | EPSS0.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |