CVE-2012-2549: Microsoft Windows Server 2008

Medium severity, CVSS 5.8. EPSS: 10% chance of exploitation in the next 30 days.

The IP-HTTPS server in Windows Server 2008 R2 and R2 SP1 and Server 2012 does not properly validate certificates, which allows remote attackers to bypass intended access restrictions via a revoked certificate, aka "Revoked Certificate Bypass Vulnerability."

Affected products

  • Microsoft Windows Server 2008: any version
  • Microsoft Windows Server 2012: affected versions not specified

Published 2012-12-12. Last modified 2026-06-16.