cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 100 of 141
CVE-2023-28241P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28241 [HIGH] CVE-2023-28241: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2020-1091P3MEDIUMCVSS 6.5≥ 6.3.0, < publication2020-09-11
CVE-2020-1091 [MEDIUM] CVE-2020-1091: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2022-35769P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.205202022-08-09
CVE-2022-35769 [HIGH] CWE-400 CVE-2022-35769: Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
nvd
CVE-2023-35338P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35338 [HIGH] CWE-476 CVE-2023-35338: Windows Peer Name Resolution Protocol Denial of Service Vulnerability Windows Peer Name Resolution Protocol Denial of Service Vulnerability
nvd
CVE-2023-32011P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210132023-06-14
CVE-2023-32011 [HIGH] CWE-125 CVE-2023-32011: Windows iSCSI Discovery Service Denial of Service Vulnerability Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-28217P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28217 [HIGH] CWE-400 CVE-2023-28217: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2022-41058P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.206712022-11-09
CVE-2022-41058 [HIGH] CVE-2022-41058: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2023-36912P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.215032023-08-08
CVE-2023-36912 [HIGH] CWE-20 CVE-2023-36912: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2018-8304P3MEDIUMCVSS 5.9v(Server Core installation)2018-07-11
CVE-2018-8304 [MEDIUM] CVE-2018-8304: A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fail A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows
nvd
CVE-2023-38172P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.215032023-08-08
CVE-2023-38172 [HIGH] CWE-126 CVE-2023-38172: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-24859P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-24859 [HIGH] CWE-476 CVE-2023-24859: Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
nvd
CVE-2023-21813P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-21813 [HIGH] CWE-126 CVE-2023-21813: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2023-32044P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-32044 [HIGH] CWE-125 CVE-2023-32044: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2023-32045P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-32045 [HIGH] CWE-125 CVE-2023-32045: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2018-8308P3MEDIUMCVSS 6.6v(Server Core installation)2018-07-11
CVE-2018-8308 [MEDIUM] CWE-404 CVE-2018-8308: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Win
nvd
CVE-2020-16997P4MEDIUMCVSS 6.5≥ 6.3.0, < publication2020-11-11
CVE-2020-16997 [MEDIUM] CVE-2020-16997: Remote Desktop Protocol Server Information Disclosure Vulnerability Remote Desktop Protocol Server Information Disclosure Vulnerability
nvd
CVE-2020-1487P3MEDIUMCVSS 6.5≥ 6.3.0, < publication2020-08-17
CVE-2020-1487 [MEDIUM] CVE-2020-1487: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log onto an affected system and open a specially crafted file. In a web-b
nvd
CVE-2023-36805P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.215632023-09-12
CVE-2023-36805 [HIGH] CWE-77 CVE-2023-36805: Windows MSHTML Platform Security Feature Bypass Vulnerability Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2021-43216P3MEDIUMCVSS 6.5≥ 6.3.0, < 6.3.9600.202072021-12-15
CVE-2021-43216 [MEDIUM] CWE-668 CVE-2021-43216: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2024-30036P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.219722024-05-14
CVE-2024-30036 [MEDIUM] CWE-41 CVE-2024-30036: Windows Deployment Services Information Disclosure Vulnerability Windows Deployment Services Information Disclosure Vulnerability
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase