Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 38 of 141
CVE-2026-50332P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50332 [HIGH] CWE-122 CVE-2026-50332: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-35420P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-35420 [HIGH] CWE-122 CVE-2026-35420: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50477P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50477 [HIGH] CWE-122 CVE-2026-50477: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-56650P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-56650 [HIGH] CWE-122 CVE-2026-56650: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50363P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50363 [HIGH] CWE-122 CVE-2026-50363: Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate pr
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50494P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50494 [HIGH] CWE-122 CVE-2026-50494: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50417P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50417 [HIGH] CWE-20 CVE-2026-50417: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-56175P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-56175 [HIGH] CWE-122 CVE-2026-56175: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges local
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-40377P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-40377 [HIGH] CWE-122 CVE-2026-40377: Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevat
Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26180P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-26180 [HIGH] CWE-122 CVE-2026-26180: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-48814P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.226762025-07-08
CVE-2025-48814 [HIGH] CWE-306 CVE-2025-48814: Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an u
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-50400P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50400 [HIGH] CWE-121 CVE-2026-50400: Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privil
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-24533P3HIGHCVSS 8.0≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-24533 [HIGH] CVE-2022-24533: Remote Desktop Protocol Remote Code Execution Vulnerability
Remote Desktop Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-36594P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36594 [HIGH] CWE-843 CVE-2023-36594: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2021-40469P3HIGHCVSS 7.2≥ 6.3.0, < 6.3.9600.201442021-10-13
CVE-2021-40469 [HIGH] CVE-2021-40469: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-21920P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.202462022-01-11
CVE-2022-21920 [HIGH] CVE-2022-21920: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2021-1706P3HIGHCVSS 8.8≥ 6.3.0, < publication2021-01-12
CVE-2021-1706 [HIGH] CWE-269 CVE-2021-1706: Windows LUAFV Elevation of Privilege Vulnerability
Windows LUAFV Elevation of Privilege Vulnerability
nvd
CVE-2022-37982P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-37982 [HIGH] CVE-2022-37982: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2022-38031P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-38031 [HIGH] CVE-2022-38031: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2023-28275P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.209192023-04-11
CVE-2023-28275 [HIGH] CWE-122 CVE-2023-28275: Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
nvd