Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 126 of 141
CVE-2022-35758P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.205202023-05-31
CVE-2022-35758 [MEDIUM] CVE-2022-35758: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2023-21697P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-21697 [MEDIUM] CWE-126 CVE-2023-21697: Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
nvd
CVE-2020-1596P4MEDIUMCVSS 5.3≥ 6.3.0, < publication2020-09-11
CVE-2020-1596 [MEDIUM] CWE-327 CVE-2020-1596: <p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An at
A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.
To exploit the vulnerability, an attacker would have to conduct a man-in-the-middle attack.
The update addresses t
nvd
CVE-2026-45606P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-45606 [MEDIUM] CWE-125 CVE-2026-45606: Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
nvd
CVE-2026-50684P4MEDIUMCVSS 4.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50684 [MEDIUM] CWE-79 CVE-2026-50684: Improper neutralization of input during web page generation ('cross-site scripting') in Active Direc
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2024-29056P4MEDIUMCVSS 4.3≥ 6.3.9600.0, < 6.3.9600.219242024-04-09
CVE-2024-29056 [MEDIUM] CWE-327 CVE-2024-29056: Windows Authentication Elevation of Privilege Vulnerability
Windows Authentication Elevation of Privilege Vulnerability
nvd
CVE-2026-32209P4MEDIUMCVSS 4.4≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-32209 [MEDIUM] CWE-284 CVE-2026-32209: Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass
Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2024-38234P4MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.221752024-09-10
CVE-2024-38234 [MEDIUM] CWE-20 CVE-2024-38234: Windows Networking Denial of Service Vulnerability
Windows Networking Denial of Service Vulnerability
nvd
CVE-2025-21347P4MEDIUMCVSS 6.0≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21347 [MEDIUM] CWE-59 CVE-2025-21347: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2018-8309P4MEDIUMCVSS 5.5v(Server Core installation)2018-07-11
CVE-2018-8309 [MEDIUM] CVE-2018-8309: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-8205P4MEDIUMCVSS 5.5v(Server Core installation)2018-06-14
CVE-2018-8205 [MEDIUM] CVE-2018-8205: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka "Windows Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2022-34708P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.205202022-08-09
CVE-2022-34708 [MEDIUM] CWE-200 CVE-2022-34708: Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2020-17036P4MEDIUMCVSS 5.5≥ 6.3.0, < publication2020-11-11
CVE-2020-17036 [MEDIUM] CVE-2020-17036: Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
nvd
CVE-2022-30223P4MEDIUMCVSS 5.7≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-30223 [MEDIUM] CVE-2022-30223: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2020-17004P4MEDIUMCVSS 5.5≥ 6.3.0, < publication2020-11-11
CVE-2020-17004 [MEDIUM] CVE-2020-17004: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2022-29114P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.203712022-05-10
CVE-2022-29114 [MEDIUM] CVE-2022-29114: Windows Print Spooler Information Disclosure Vulnerability
Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2020-1038P4MEDIUMCVSS 5.5≥ 6.3.0, < publication2020-09-11
CVE-2020-1038 [MEDIUM] CVE-2020-1038: <p>A denial of service vulnerability exists when Windows Routing Utilities improperly handles object
A denial of service vulnerability exists when Windows Routing Utilities improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability w
nvd
CVE-2024-26177P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.218712024-03-12
CVE-2024-26177 [MEDIUM] CWE-200 CVE-2024-26177: Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2024-26174P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.218712024-03-12
CVE-2024-26174 [MEDIUM] CWE-125 CVE-2024-26174: Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2024-38017P4MEDIUMCVSS 5.5≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38017 [MEDIUM] CWE-200 CVE-2024-38017: Microsoft Message Queuing Information Disclosure Vulnerability
Microsoft Message Queuing Information Disclosure Vulnerability
nvd