Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 18 of 141
CVE-2024-26230P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.219242024-04-09
CVE-2024-26230 [HIGH] CWE-416 CVE-2024-26230: Windows Telephony Server Elevation of Privilege Vulnerability
Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2025-21285P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21285 [HIGH] CWE-476 CVE-2025-21285: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2021-28445P3HIGHCVSS 8.8≥ 6.3.0, < publication2021-04-13
CVE-2021-28445 [HIGH] CVE-2021-28445: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2025-21371P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2021-33780P3HIGHCVSS 8.8≥ 6.3.0, < 6.3.9600.200692021-07-14
CVE-2021-33780 [HIGH] CVE-2021-33780: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-24088P3HIGHCVSS 8.8≥ 6.3.0, < publication2021-02-25
CVE-2021-24088 [HIGH] CVE-2021-24088: Windows Local Spooler Remote Code Execution Vulnerability
Windows Local Spooler Remote Code Execution Vulnerability
nvd
CVE-2022-23294P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.203032022-03-09
CVE-2022-23294 [HIGH] CVE-2022-23294: Windows Event Tracing Remote Code Execution Vulnerability
Windows Event Tracing Remote Code Execution Vulnerability
nvd
CVE-2026-24294P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.230742026-03-10
CVE-2026-24294 [HIGH] CWE-287 CVE-2026-24294: Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges lo
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-50177P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.227252025-08-12
CVE-2025-50177 [HIGH] CWE-362 CVE-2025-50177: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-28455P3HIGHCVSS 8.8≥ 6.3.0, < 6.3.9600.200172021-05-11
CVE-2021-28455 [HIGH] CVE-2021-28455: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
nvd
CVE-2021-34525P3HIGHCVSS 8.8≥ 6.3.0, < 6.3.9600.200692021-07-14
CVE-2021-34525 [HIGH] CVE-2021-34525: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2025-21407P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21407 [HIGH] CWE-122 CVE-2025-21407: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21406P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21406 [HIGH] CWE-416 CVE-2025-21406: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21190P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21190 [HIGH] CWE-122 CVE-2025-21190: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21201P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability
Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21200P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21200 [HIGH] CWE-122 CVE-2025-21200: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2021-33746P3HIGHCVSS 8.8≥ 6.3.0, < 6.3.9600.200692021-07-14
CVE-2021-33746 [HIGH] CVE-2021-33746: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35322P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35322 [HIGH] CWE-121 CVE-2023-35322: Windows Deployment Services Remote Code Execution Vulnerability
Windows Deployment Services Remote Code Execution Vulnerability
nvd
CVE-2025-54106P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54106 [HIGH] CWE-190 CVE-2025-54106: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unautho
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-21695P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-21695 [HIGH] CWE-122 CVE-2023-21695: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
nvd