Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 123 of 141
CVE-2021-31970P4MEDIUMCVSS 5.5≥ 6.3.0, < 6.3.9600.20045≥ 6.3.0, < 6.3.9600.200442021-06-08
CVE-2021-31970 [MEDIUM] CWE-639 CVE-2021-31970: Windows TCP/IP Driver Security Feature Bypass Vulnerability
Windows TCP/IP Driver Security Feature Bypass Vulnerability
nvd
CVE-2025-27742P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-27742 [MEDIUM] CWE-125 CVE-2025-27742: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-26207P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.219722024-04-09
CVE-2024-26207 [MEDIUM] CWE-125 CVE-2024-26207: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-28902P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.219722024-04-09
CVE-2024-28902 [MEDIUM] CWE-126 CVE-2024-28902: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-30039P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.219722024-05-14
CVE-2024-30039 [MEDIUM] CWE-126 CVE-2024-30039: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-38203P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.222672024-11-12
CVE-2024-38203 [MEDIUM] CWE-693 CVE-2024-38203: Windows Package Library Manager Information Disclosure Vulnerability
Windows Package Library Manager Information Disclosure Vulnerability
nvd
CVE-2024-28900P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.219722024-04-09
CVE-2024-28900 [MEDIUM] CWE-126 CVE-2024-28900: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-28901P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.219242024-04-09
CVE-2024-28901 [MEDIUM] CWE-126 CVE-2024-28901: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-38118P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.221342024-08-13
CVE-2024-38118 [MEDIUM] CWE-908 CVE-2024-38118: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2024-38122P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.221342024-08-13
CVE-2024-38122 [MEDIUM] CWE-908 CVE-2024-38122: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2023-36724P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36724 [MEDIUM] CWE-287 CVE-2023-36724: Windows Power Management Service Information Disclosure Vulnerability
Windows Power Management Service Information Disclosure Vulnerability
nvd
CVE-2025-59190P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.228242025-10-14
CVE-2025-59190 [MEDIUM] CWE-20 CVE-2025-59190: Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to d
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2023-23394P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-23394 [MEDIUM] CWE-822 CVE-2023-23394: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2023-23409P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-23409 [MEDIUM] CWE-20 CVE-2023-23409: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2026-25168P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.230742026-03-10
CVE-2026-25168 [MEDIUM] CWE-476 CVE-2026-25168: Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny ser
Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2024-20662P4MEDIUMCVSS 4.9≥ 6.3.9600.0, < 6.3.9600.217652024-01-09
CVE-2024-20662 [MEDIUM] CWE-843 CVE-2024-20662: Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
nvd
CVE-2019-0941P4MEDIUMCVSS 4.4≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0941 [MEDIUM] CWE-19 CVE-2019-0941: A denial of service exists in Microsoft IIS Server when the optional request filtering feature impro
A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use request filtering.
To exploit this vulnerability, an attacker could send a specially crafted req
nvd
CVE-2025-21328P4MEDIUMCVSS 4.3≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21328 [MEDIUM] CWE-41 CVE-2025-21328: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21329P4MEDIUMCVSS 4.3≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21329 [MEDIUM] CWE-41 CVE-2025-21329: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21352P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21352 [MEDIUM] CWE-400 CVE-2025-21352: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd