Microsoft Windows Server 2012 R2 vulnerabilities

2,572 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,572
CISA KEV
96
actively exploited
Public exploits
54
Exploited in wild
85
Severity breakdown
CRITICAL85HIGH1805MEDIUM672LOW10

Vulnerabilities

Page 12 of 129
CVE-2025-54093HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54093 [HIGH] CWE-367 CVE-2025-54093: Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-54895HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54895 [HIGH] CWE-190 CVE-2025-54895: Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-54113HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54113 [HIGH] CWE-122 CVE-2025-54113: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
cvelistv5nvd
CVE-2025-54106HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54106 [HIGH] CWE-190 CVE-2025-54106: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unautho Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
cvelistv5nvd
CVE-2025-54110HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54110 [HIGH] CWE-190 CVE-2025-54110: Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-54099HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54099 [HIGH] CWE-121 CVE-2025-54099: Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized at Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-54918HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54918 [HIGH] CWE-287 CVE-2025-54918: Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a n Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
cvelistv5nvd
CVE-2025-54916HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54916 [HIGH] CWE-121 CVE-2025-54916: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
cvelistv5nvd
CVE-2025-54091HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54091 [HIGH] CWE-122 CVE-2025-54091: Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privilege Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-54894HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54894 [HIGH] CWE-122 CVE-2025-54894: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2025-54911HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54911 [HIGH] CWE-416 CVE-2025-54911: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-54912HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54912 [HIGH] CWE-416 CVE-2025-54912: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-54098HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54098 [HIGH] CWE-284 CVE-2025-54098: Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges local Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-53804MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-53804 [MEDIUM] CWE-200 CVE-2025-53804: Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized at Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2025-54107MEDIUMCVSS 4.3≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54107 [MEDIUM] CWE-41 CVE-2025-54107: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to b Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
cvelistv5nvd
CVE-2025-53798MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-53798 [MEDIUM] CWE-126 CVE-2025-53798: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
cvelistv5nvd
CVE-2025-53810MEDIUMCVSS 6.7≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-53810 [MEDIUM] CWE-843 CVE-2025-53810: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-53803MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-53803 [MEDIUM] CWE-209 CVE-2025-53803: Generation of error message containing sensitive information in Windows Kernel allows an authorized Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
cvelistv5nvd
CVE-2025-53799MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-53799 [MEDIUM] CWE-908 CVE-2025-53799: Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclo Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
cvelistv5nvd
CVE-2025-53808MEDIUMCVSS 6.7≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-53808 [MEDIUM] CWE-843 CVE-2025-53808: Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service a Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
cvelistv5nvd