cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 3 of 141
CVE-2022-21919P1HIGHCVSS 7.0KEVPoC≥ 6.3.9600.0, < 6.3.9600.202462022-01-11
CVE-2022-21919 [HIGH] CWE-59 CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2020-17087P1HIGHCVSS 7.8KEVPoC≥ 6.3.0, < publication2020-11-11
CVE-2020-17087 [HIGH] CWE-131 CVE-2020-17087: Windows Kernel Local Elevation of Privilege Vulnerability Windows Kernel Local Elevation of Privilege Vulnerability
nvd
CVE-2023-28229P1HIGHCVSS 7.0KEVPoC≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28229 [HIGH] CWE-591 CVE-2023-28229: Windows CNG Key Isolation Service Elevation of Privilege Vulnerability Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
nvd
CVE-2018-8611P1HIGHCVSS 7.8KEVPoCv(Server Core installation)2018-12-12
CVE-2018-8611 [HIGH] CWE-404 CVE-2018-8611: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2026-20805P2MEDIUMCVSS 5.5KEVPoC≥ 6.3.9600.0, < 6.3.9600.229682026-01-13
CVE-2026-20805 [MEDIUM] CWE-200 CVE-2026-20805: Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an auth Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2021-33742P1HIGHCVSS 8.8KEV≥ 6.3.0, < 6.3.9600.20045≥ 6.3.0, < 1.0.0.02021-06-08
CVE-2021-33742 [HIGH] CWE-787 CVE-2021-33742: Windows MSHTML Platform Remote Code Execution Vulnerability Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2024-43572P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-43572 [HIGH] CWE-707 CVE-2024-43572: Microsoft Management Console Remote Code Execution Vulnerability Microsoft Management Console Remote Code Execution Vulnerability
nvd
CVE-2022-34713P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.205202022-08-09
CVE-2022-34713 [HIGH] CVE-2022-34713: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
nvd
CVE-2026-21510P1HIGHCVSS 8.8KEV≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21510 [HIGH] CWE-693 CVE-2026-21510: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-41128P1HIGHCVSS 8.8KEV≥ 6.3.9600.0, < 6.3.9600.206712022-11-09
CVE-2022-41128 [HIGH] CWE-787 CVE-2022-41128: Windows Scripting Languages Remote Code Execution Vulnerability Windows Scripting Languages Remote Code Execution Vulnerability
nvd
CVE-2026-21513P1HIGHCVSS 8.8KEV≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21513 [HIGH] CWE-693 CVE-2026-21513: Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a securit Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-36036P1HIGHCVSS 7.8KEVRansomware≥ 6.3.9600.0, < 6.3.9600.216682023-11-14
CVE-2023-36036 [HIGH] CWE-122 CVE-2023-36036: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-23376P1HIGHCVSS 7.8KEVRansomware≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-23376 [HIGH] CWE-122 CVE-2023-23376: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-26169P1HIGHCVSS 7.8KEVRansomware≥ 6.3.9600.0, < 6.3.9600.218712024-03-12
CVE-2024-26169 [HIGH] CWE-269 CVE-2024-26169: Windows Error Reporting Service Elevation of Privilege Vulnerability Windows Error Reporting Service Elevation of Privilege Vulnerability
nvd
CVE-2022-41073P1HIGHCVSS 7.8KEVRansomware≥ 6.3.9600.0, < 6.3.9600.206712022-11-09
CVE-2022-41073 [HIGH] CWE-787 CVE-2022-41073: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2026-56155P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-56155 [HIGH] CWE-1220 CVE-2026-56155: Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-1464P2MEDIUMCVSS 5.5KEV≥ 6.3.0, < publication2020-08-17
CVE-2020-1464 [MEDIUM] CWE-347 CVE-2020-1464: A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update address
nvd
CVE-2026-21533P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21533 [HIGH] CWE-269 CVE-2026-21533: Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate pri Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-22718P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.202692022-02-09
CVE-2022-22718 [HIGH] CVE-2022-22718: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2025-24983P1HIGHCVSS 7.0KEV≥ 6.3.9600.0, < 6.3.9600.224702025-03-11
CVE-2025-24983 [HIGH] CWE-416 CVE-2025-24983: Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase