cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,562 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,562
CISA KEV
96
actively exploited
Public exploits
62
Exploited in wild
82
Severity breakdown
CRITICAL86HIGH1814MEDIUM653LOW9

Vulnerabilities

Page 1 of 129
CVE-2026-41089CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-41089 [CRITICAL] CWE-121 CVE-2026-41089: Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-34333HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34333 [HIGH] CWE-190 CVE-2026-34333: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35415HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-35415 [HIGH] CWE-190 CVE-2026-35415: Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34330HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34330 [HIGH] CWE-190 CVE-2026-34330: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33837HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-33837 [HIGH] CWE-122 CVE-2026-33837: Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40403HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-40403 [HIGH] CWE-122 CVE-2026-40403: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code lo Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
nvd
CVE-2026-32161HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-32161 [HIGH] CWE-362 CVE-2026-32161: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2026-34329HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34329 [HIGH] CWE-122 CVE-2026-34329: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2026-40401HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-40401 [HIGH] CWE-476 CVE-2026-40401: Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally. Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service locally.
nvd
CVE-2026-34338HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34338 [HIGH] CWE-416 CVE-2026-34338: Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges loca Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40398HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-40398 [HIGH] CWE-122 CVE-2026-40398: Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privil Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34343HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34343 [HIGH] CWE-122 CVE-2026-34343: Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized at Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40410HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-40410 [HIGH] CWE-416 CVE-2026-40410: Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally. Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40377HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-40377 [HIGH] CWE-122 CVE-2026-40377: Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35424HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-35424 [HIGH] CWE-401 CVE-2026-35424: Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol a Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-34341HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34341 [HIGH] CWE-415 CVE-2026-34341: Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-41095HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-41095 [HIGH] CWE-416 CVE-2026-41095: Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally. Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33838HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-33838 [HIGH] CWE-415 CVE-2026-33838: Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally. Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40408HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-40408 [HIGH] CWE-416 CVE-2026-40408: Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges lo Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
nvd
1 / 129Next →
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase