cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 111 of 141
CVE-2022-22022P4HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-22022 [HIGH] CVE-2022-22022: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-30226P4HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-30226 [HIGH] CVE-2022-30226: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-35837P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.205712022-09-13
CVE-2022-35837 [MEDIUM] CVE-2022-35837: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-34690P4HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.205202022-08-09
CVE-2022-34690 [HIGH] CVE-2022-34690: Windows Fax Service Elevation of Privilege Vulnerability Windows Fax Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21760P4HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21760 [HIGH] CWE-59 CVE-2023-21760: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2023-29369P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210132023-06-14
CVE-2023-29369 [MEDIUM] CWE-190 CVE-2023-29369: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2022-38006P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.205712022-09-13
CVE-2022-38006 [MEDIUM] CVE-2022-38006: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2018-0976P4MEDIUMCVSS 5.3v(Server Core installation)2018-04-12
CVE-2018-0976 [MEDIUM] CVE-2018-0976: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.
nvd
CVE-2022-37977P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-37977 [MEDIUM] CVE-2022-37977: Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
nvd
CVE-2023-35318P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35318 [MEDIUM] CWE-125 CVE-2023-35318: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-35319P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35319 [MEDIUM] CWE-125 CVE-2023-35319: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-35314P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35314 [MEDIUM] CWE-125 CVE-2023-35314: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33164P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33164 [MEDIUM] CWE-125 CVE-2023-33164: Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2025-50158P4HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.227252025-08-12
CVE-2025-50158 [HIGH] CWE-367 CVE-2025-50158: Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2021-33764P4MEDIUMCVSS 5.9≥ 6.3.0, < 6.3.9600.200692021-07-14
CVE-2021-33764 [MEDIUM] CVE-2021-33764: Windows Key Distribution Center Information Disclosure Vulnerability Windows Key Distribution Center Information Disclosure Vulnerability
nvd
CVE-2023-21560P4MEDIUMCVSS 6.6≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21560 [MEDIUM] CWE-122 CVE-2023-21560: Windows Boot Manager Security Feature Bypass Vulnerability Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28269P4MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28269 [MEDIUM] CWE-122 CVE-2023-28269: Windows Boot Manager Security Feature Bypass Vulnerability Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2023-28249P4MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28249 [MEDIUM] CWE-863 CVE-2023-28249: Windows Boot Manager Security Feature Bypass Vulnerability Windows Boot Manager Security Feature Bypass Vulnerability
nvd
CVE-2024-38013P4MEDIUMCVSS 6.7≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38013 [MEDIUM] CWE-59 CVE-2024-38013: Microsoft Windows Server Backup Elevation of Privilege Vulnerability Microsoft Windows Server Backup Elevation of Privilege Vulnerability
nvd
CVE-2026-45608P4MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-45608 [MEDIUM] CWE-125 CVE-2026-45608: Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information lo Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase