Microsoft Windows Server 2012 R2 vulnerabilities
3,402 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
3,402
CISA KEV
100
actively exploited
Public exploits
96
Exploited in wild
134
Severity breakdown
CRITICAL137HIGH2398MEDIUM855LOW12
Vulnerabilities
Page 3 of 171
CVE-2022-26904P1HIGHCVSS 7.0KEVPoC≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-26904 [HIGH] CWE-362 CVE-2022-26904: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21919P1HIGHCVSS 7.0KEVPoC≥ 6.3.9600.0, < 6.3.9600.202462022-01-11
CVE-2022-21919 [HIGH] CWE-59 CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2020-17087P1HIGHCVSS 7.8KEVPoC≥ 6.3.0, < publication2020-11-11
CVE-2020-17087 [HIGH] CWE-131 CVE-2020-17087: Windows Kernel Local Elevation of Privilege Vulnerability
Windows Kernel Local Elevation of Privilege Vulnerability
nvd
CVE-2023-28229P1HIGHCVSS 7.0KEVPoC≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28229 [HIGH] CWE-591 CVE-2023-28229: Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
nvd
CVE-2018-8611P1HIGHCVSS 7.8KEVPoCv(Server Core installation)2018-12-12
CVE-2018-8611 [HIGH] CWE-404 CVE-2018-8611: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2026-20805P2MEDIUMCVSS 5.5KEVPoC≥ 6.3.9600.0, < 6.3.9600.229682026-01-13
CVE-2026-20805 [MEDIUM] CWE-200 CVE-2026-20805: Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an auth
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
nvd
CVE-2021-33742P1HIGHCVSS 8.8KEV≥ 6.3.0, < 6.3.9600.20045≥ 6.3.0, < 1.0.0.02021-06-08
CVE-2021-33742 [HIGH] CWE-787 CVE-2021-33742: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2024-43572P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-43572 [HIGH] CWE-707 CVE-2024-43572: Microsoft Management Console Remote Code Execution Vulnerability
Microsoft Management Console Remote Code Execution Vulnerability
nvd
CVE-2022-34713P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.205202022-08-09
CVE-2022-34713 [HIGH] CVE-2022-34713: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
nvd
CVE-2026-21510P1HIGHCVSS 8.8KEV≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21510 [HIGH] CWE-693 CVE-2026-21510: Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security f
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2022-41128P1HIGHCVSS 8.8KEV≥ 6.3.9600.0, < 6.3.9600.206712022-11-09
CVE-2022-41128 [HIGH] CWE-787 CVE-2022-41128: Windows Scripting Languages Remote Code Execution Vulnerability
Windows Scripting Languages Remote Code Execution Vulnerability
nvd
CVE-2026-21513P1HIGHCVSS 8.8KEV≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21513 [HIGH] CWE-693 CVE-2026-21513: Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a securit
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-36036P1HIGHCVSS 7.8KEVRansomware≥ 6.3.9600.0, < 6.3.9600.216682023-11-14
CVE-2023-36036 [HIGH] CWE-122 CVE-2023-36036: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2026-85880P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.233972026-09-08
CVE-2026-85880 [HIGH] CWE-122 CVE-2026-85880: Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges local
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-23376P1HIGHCVSS 7.8KEVRansomware≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-23376 [HIGH] CWE-122 CVE-2023-23376: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-26169P1HIGHCVSS 7.8KEVRansomware≥ 6.3.9600.0, < 6.3.9600.218712024-03-12
CVE-2024-26169 [HIGH] CWE-269 CVE-2024-26169: Windows Error Reporting Service Elevation of Privilege Vulnerability
Windows Error Reporting Service Elevation of Privilege Vulnerability
nvd
CVE-2022-41073P1HIGHCVSS 7.8KEVRansomware≥ 6.3.9600.0, < 6.3.9600.206712022-11-09
CVE-2022-41073 [HIGH] CWE-787 CVE-2022-41073: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-22047P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-22047 [HIGH] CWE-426 CVE-2022-22047: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2026-68820P1HIGHCVSS 7.0KEV≥ 6.3.9600.0, < 6.3.9600.233382026-08-11
CVE-2026-68820 [HIGH] CWE-416 CVE-2026-68820: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21533P1HIGHCVSS 7.8KEV≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21533 [HIGH] CWE-269 CVE-2026-21533: Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate pri
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
nvd