Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 103 of 141
CVE-2020-0875P3MEDIUMCVSS 5.5≥ 6.3.0, < publication2020-09-11
CVE-2020-0875 [MEDIUM] CVE-2020-0875: <p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An atta
An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity).
This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to
nvd
CVE-2023-36706P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36706 [MEDIUM] CWE-20 CVE-2023-36706: Windows Deployment Services Information Disclosure Vulnerability
Windows Deployment Services Information Disclosure Vulnerability
nvd
CVE-2022-23298P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.203032022-03-09
CVE-2022-23298 [HIGH] CVE-2022-23298: Windows NT OS Kernel Elevation of Privilege Vulnerability
Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38022P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38022 [HIGH] CWE-59 CVE-2024-38022: Windows Image Acquisition Elevation of Privilege Vulnerability
Windows Image Acquisition Elevation of Privilege Vulnerability
nvd
CVE-2023-36403P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.216682023-11-14
CVE-2023-36403 [HIGH] CWE-591 CVE-2023-36403: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43535P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-43535 [HIGH] CWE-416 CVE-2024-43535: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43570P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-43570 [HIGH] CWE-416 CVE-2024-43570: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-49084P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.223182024-12-12
CVE-2024-49084 [HIGH] CWE-362 CVE-2024-49084: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-29364P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.210132023-06-14
CVE-2023-29364 [HIGH] CWE-190 CVE-2023-29364: Windows Authentication Elevation of Privilege Vulnerability
Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2025-21191P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-21191 [HIGH] CWE-367 CVE-2025-21191: Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows a
Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-38033P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-38033 [MEDIUM] CVE-2022-38033: Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability
nvd
CVE-2023-24865P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-24865 [MEDIUM] CWE-20 CVE-2023-24865: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-24866P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-24866 [MEDIUM] CWE-20 CVE-2023-24866: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2023-35296P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35296 [MEDIUM] CWE-125 CVE-2023-35296: Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
nvd
CVE-2026-26152P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-26152 [HIGH] CWE-922 CVE-2026-26152: Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized att
Insecure storage of sensitive information in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27468P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.225772025-05-13
CVE-2025-27468 [HIGH] CWE-269 CVE-2025-27468: Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate
Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-41097P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.206712022-11-09
CVE-2022-41097 [MEDIUM] CVE-2022-41097: Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability
nvd
CVE-2023-35316P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35316 [MEDIUM] CWE-125 CVE-2023-35316: Remote Procedure Call Runtime Information Disclosure Vulnerability
Remote Procedure Call Runtime Information Disclosure Vulnerability
nvd
CVE-2023-36564P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36564 [MEDIUM] CVE-2023-36564: Windows Search Security Feature Bypass Vulnerability
Windows Search Security Feature Bypass Vulnerability
nvd
CVE-2023-35332P4MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35332 [MEDIUM] CWE-326 CVE-2023-35332: Windows Remote Desktop Protocol Security Feature Bypass
Windows Remote Desktop Protocol Security Feature Bypass
nvd