cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 14 of 141
CVE-2026-48564P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.232282026-07-14
CVE-2026-48564 [HIGH] CWE-122 CVE-2026-48564: Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50444P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50444 [HIGH] CWE-306 CVE-2026-50444: Missing authentication for critical function in Windows Server Update Service allows an authorized a Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50502P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50502 [HIGH] CWE-1220 CVE-2026-50502: Insufficient granularity of access control in Windows Event Logging Service allows an authorized att Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
nvd
CVE-2022-34722P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.205712022-09-13
CVE-2022-34722 [CRITICAL] CVE-2022-34722: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2019-0722P2HIGHCVSS 8.8≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0722 [HIGH] CWE-20 CVE-2019-0722: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary
nvd
CVE-2022-35744P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.205202023-05-31
CVE-2022-35744 [CRITICAL] CVE-2022-35744: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2023-36606P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2018-8134P3HIGHCVSS 7.0PoCv(Server Core installation)2018-05-09
CVE-2018-8134 [HIGH] CVE-2018-8134: An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permi An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2026-56159P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-56159 [CRITICAL] CWE-122 CVE-2026-56159: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code ov Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-50447P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50447 [CRITICAL] CWE-122 CVE-2026-50447: Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute cod Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58594P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-58594 [CRITICAL] CWE-190 CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-42990P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.232282026-07-14
CVE-2026-42990 [CRITICAL] CWE-122 CVE-2026-42990: Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-57089P2CRITICALCVSS 9.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-57089 [CRITICAL] CWE-416 CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized at Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2018-8225P3HIGHCVSS 8.1v(Server Core installation)2018-06-14
CVE-2018-8225 [HIGH] CVE-2018-8225: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2024-38104P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38104 [HIGH] CWE-822 CVE-2024-38104: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-38116P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.221342024-08-13
CVE-2024-38116 [HIGH] CWE-122 CVE-2024-38116: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-43611P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-43611 [HIGH] CWE-20 CVE-2024-43611: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-49080P2HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.223182024-12-12
CVE-2024-49080 [HIGH] CWE-122 CVE-2024-49080: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2025-21376P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21376 [HIGH] CWE-122 CVE-2025-21376: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2018-1004P3HIGHCVSS 8.8v(Server Core installation)2018-04-12
CVE-2018-1004 [HIGH] CWE-787 CVE-2018-1004: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10.
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase