Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 10 of 141
CVE-2021-24078P2CRITICALCVSS 9.8≥ 6.3.0, < publication2021-02-25
CVE-2021-24078 [CRITICAL] CVE-2021-24078: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2025-49730P3HIGHCVSS 7.8PoC≥ 6.3.9600.0, < 6.3.9600.226762025-07-08
CVE-2025-49730 [HIGH] CWE-122 CVE-2025-49730: Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an autho
Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-23285P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.203032022-03-09
CVE-2022-23285 [HIGH] CVE-2022-23285: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2023-28231P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28231 [HIGH] CWE-122 CVE-2023-28231: DHCP Server Service Remote Code Execution Vulnerability
DHCP Server Service Remote Code Execution Vulnerability
nvd
CVE-2024-49122P2HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.223182024-12-12
CVE-2024-49122 [HIGH] CWE-416 CVE-2024-49122: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2018-8411P3HIGHCVSS 7.8PoCv(Server Core installation)2018-10-10
CVE-2018-8411 [HIGH] CWE-732 CVE-2018-8411: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0570P3HIGHCVSS 7.8PoCv(Server Core installation)2019-01-08
CVE-2019-0570 [HIGH] CWE-416 CVE-2019-0570: An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects i
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2019-0943P3HIGHCVSS 7.8PoC≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0943 [HIGH] CVE-2019-0943: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user
nvd
CVE-2026-50330P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50330 [CRITICAL] CWE-122 CVE-2026-50330: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privi
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-44815P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-44815 [CRITICAL] CWE-121 CVE-2026-44815: Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code o
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-17051P2CRITICALCVSS 9.8≥ 6.3.0, < publication2020-11-11
CVE-2020-17051 [CRITICAL] CVE-2020-17051: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2025-53143P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.227252025-08-12
CVE-2025-53143 [HIGH] CWE-843 CVE-2025-53143: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2023-28302P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28302 [HIGH] CWE-20 CVE-2023-28302: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-53145P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.227252025-08-12
CVE-2025-53145 [HIGH] CWE-843 CVE-2025-53145: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2025-53144P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.227252025-08-12
CVE-2025-53144 [HIGH] CWE-843 CVE-2025-53144: Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an a
Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker to execute code over a network.
nvd
CVE-2018-8626P2CRITICALCVSS 9.8v(Server Core installation)2018-12-12
CVE-2018-8626 [CRITICAL] CWE-787 CVE-2018-8626: A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they f
A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "Windows DNS Server Heap Overflow Vulnerability." This affects Windows Server 2012 R2, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
nvd
CVE-2021-26895P2CRITICALCVSS 9.8≥ 6.3.0, < publication2021-03-11
CVE-2021-26895 [CRITICAL] CVE-2021-26895: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-26894P2CRITICALCVSS 9.8≥ 6.3.0, < publication2021-03-11
CVE-2021-26894 [CRITICAL] CVE-2021-26894: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-36936P2CRITICALCVSS 9.8≥ 6.3.0, < 6.3.9600.200942021-08-12
CVE-2021-36936 [CRITICAL] CVE-2021-36936: Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2021-26893P2CRITICALCVSS 9.8≥ 6.3.0, < publication2021-03-11
CVE-2021-26893 [CRITICAL] CVE-2021-26893: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd