cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 12 of 141
CVE-2025-21368P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21368 [HIGH] CWE-122 CVE-2025-21368: Microsoft Digest Authentication Remote Code Execution Vulnerability Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2023-36017P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.216682023-11-14
CVE-2023-36017 [HIGH] CWE-843 CVE-2023-36017: Windows Scripting Engine Memory Corruption Vulnerability Windows Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2025-21309P2HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21309 [HIGH] CWE-591 CVE-2025-21309: Windows Remote Desktop Services Remote Code Execution Vulnerability Windows Remote Desktop Services Remote Code Execution Vulnerability
nvd
CVE-2026-56194P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-56194 [HIGH] CWE-122 CVE-2026-56194: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-56647P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-56647 [HIGH] CWE-190 CVE-2026-56647: Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2021-36965P2CRITICALCVSS 9.8≥ 6.3.0, < 6.3.9600.201202021-09-15
CVE-2021-36965 [CRITICAL] CVE-2021-36965: Windows WLAN AutoConfig Service Remote Code Execution Vulnerability Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
nvd
CVE-2024-26212P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.219242024-04-09
CVE-2024-26212 [HIGH] CWE-400 CVE-2024-26212: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2023-36910P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.215032023-08-08
CVE-2023-36910 [CRITICAL] CWE-190 CVE-2023-36910: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-35385P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.215032023-08-08
CVE-2023-35385 [CRITICAL] CWE-190 CVE-2023-35385: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-38199P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.221342024-08-13
CVE-2024-38199 [CRITICAL] CWE-416 CVE-2024-38199: Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
nvd
CVE-2023-32057P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-32057 [CRITICAL] CWE-20 CVE-2023-32057: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2018-8256P3HIGHCVSS 8.8v(Server Core installation)2018-11-14
CVE-2018-8256 [HIGH] CVE-2018-8256: A remote code execution vulnerability exists when PowerShell improperly handles specially crafted fi A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008 R2, Windows Server 2019, Windows 7, Windows
nvd
CVE-2025-21307P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21307 [CRITICAL] CWE-416 CVE-2025-21307: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
nvd
CVE-2023-36005P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.217152023-12-12
CVE-2023-36005 [HIGH] CWE-591 CVE-2023-36005: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2018-8450P2HIGHCVSS 8.8v(Server Core installation)2018-11-14
CVE-2018-8450 [HIGH] CWE-404 CVE-2018-8450: A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Win A remote code execution vulnerability exists when Windows Search handles objects in memory, aka "Windows Search Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2026-57092P2CRITICALCVSS 9.9≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-57092 [CRITICAL] CWE-416 CVE-2026-57092: Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a networ Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2018-8344P3HIGHCVSS 8.8v(Server Core installation)2018-08-15
CVE-2018-8344 [HIGH] CWE-94 CVE-2018-8344: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2026-54995P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-54995 [CRITICAL] CWE-416 CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to ex Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-21746HIGHCVSS 7.8ExploitedPoC≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21746 [HIGH] Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability Windows NTLM Elevation of Privilege Vulnerability
cvelistv5
CVE-2020-1074P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-09-11
CVE-2020-1074 [HIGH] CVE-2020-1074: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase