Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 111 of 141
CVE-2022-22022P4HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-22022 [HIGH] CVE-2022-22022: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-30226P4HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-30226 [HIGH] CVE-2022-30226: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-35837P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.205712022-09-13
CVE-2022-35837 [MEDIUM] CVE-2022-35837: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-34690P4HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.205202022-08-09
CVE-2022-34690 [HIGH] CVE-2022-34690: Windows Fax Service Elevation of Privilege Vulnerability
Windows Fax Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21760P4HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21760 [HIGH] CWE-59 CVE-2023-21760: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2023-29369P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210132023-06-14
CVE-2023-29369 [MEDIUM] CWE-190 CVE-2023-29369: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2022-38006P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.205712022-09-13
CVE-2022-38006 [MEDIUM] CVE-2022-38006: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2018-0976P4MEDIUMCVSS 5.3v(Server Core installation)2018-04-12
CVE-2018-0976 [MEDIUM] CVE-2018-0976: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.
nvd
CVE-2022-37977P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-37977 [MEDIUM] CVE-2022-37977: Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
nvd
CVE-2023-35318P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35318 [MEDIUM] CWE-125 CVE-2023-35318: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-35319P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35319 [MEDIUM] CWE-125 CVE-2023-35319: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-35314P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35314 [MEDIUM] CWE-125 CVE-2023-35314: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33164P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33164 [MEDIUM] CWE-125 CVE-2023-33164: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2025-50158P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.227252025-08-12
CVE-2025-50158 [HIGH] CWE-367 CVE-2025-50158: Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to
Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2021-33764P4MEDIUMCVSS 5.9≥ 6.3.0, < 6.3.9600.200692021-07-14
CVE-2021-33764 [MEDIUM] CVE-2021-33764: Windows Key Distribution Center Information Disclosure Vulnerability
Windows Key Distribution Center Information Disclosure Vulnerability
nvd
CVE-2023-21560P4MEDIUMCVSS 6.6≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21560 [MEDIUM] CWE-122 CVE-2023-21560: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28269P4MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28269 [MEDIUM] CWE-122 CVE-2023-28269: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28249P4MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28249 [MEDIUM] CWE-863 CVE-2023-28249: Windows Boot Manager Security Feature Bypass Vulnerability
Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2024-38013P4MEDIUMCVSS 6.7≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38013 [MEDIUM] CWE-59 CVE-2024-38013: Microsoft Windows Server Backup Elevation of Privilege Vulnerability
Microsoft Windows Server Backup Elevation of Privilege Vulnerability
nvd
CVE-2026-45608P4MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-45608 [MEDIUM] CWE-125 CVE-2026-45608: Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information lo
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
nvd