cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 38 of 141
CVE-2026-50332P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50332 [HIGH] CWE-122 CVE-2026-50332: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35420P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-35420 [HIGH] CWE-122 CVE-2026-35420: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50477P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50477 [HIGH] CWE-122 CVE-2026-50477: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56650P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-56650 [HIGH] CWE-122 CVE-2026-56650: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50363P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50363 [HIGH] CWE-122 CVE-2026-50363: Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate pr Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50494P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50494 [HIGH] CWE-122 CVE-2026-50494: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50417P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50417 [HIGH] CWE-20 CVE-2026-50417: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-56175P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-56175 [HIGH] CWE-122 CVE-2026-56175: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges local Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40377P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-40377 [HIGH] CWE-122 CVE-2026-40377: Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26180P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-26180 [HIGH] CWE-122 CVE-2026-26180: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48814P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.226762025-07-08
CVE-2025-48814 [HIGH] CWE-306 CVE-2025-48814: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an u Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-50400P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50400 [HIGH] CWE-121 CVE-2026-50400: Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privil Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-24533P3HIGHCVSS 8.0≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-24533 [HIGH] CVE-2022-24533: Remote Desktop Protocol Remote Code Execution Vulnerability Remote Desktop Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-36594P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36594 [HIGH] CWE-843 CVE-2023-36594: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2021-40469P3HIGHCVSS 7.2≥ 6.3.0, < 6.3.9600.201442021-10-13
CVE-2021-40469 [HIGH] CVE-2021-40469: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-21920P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.202462022-01-11
CVE-2022-21920 [HIGH] CVE-2022-21920: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2021-1706P3HIGHCVSS 8.8≥ 6.3.0, < publication2021-01-12
CVE-2021-1706 [HIGH] CWE-269 CVE-2021-1706: Windows LUAFV Elevation of Privilege Vulnerability Windows LUAFV Elevation of Privilege Vulnerability
nvd
CVE-2022-37982P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-37982 [HIGH] CVE-2022-37982: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2022-38031P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-38031 [HIGH] CVE-2022-38031: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-28275P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28275 [HIGH] CWE-122 CVE-2023-28275: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase