Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 40 of 141
CVE-2023-41765P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-41765 [HIGH] CWE-416 CVE-2023-41765: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41769P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-41769 [HIGH] CWE-416 CVE-2023-41769: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-41770P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-41770 [HIGH] CWE-416 CVE-2023-41770: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2026-42986P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-42986 [HIGH] CWE-416 CVE-2026-42986: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-35297P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35297 [HIGH] CWE-843 CVE-2023-35297: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28283P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.209692023-05-09
CVE-2023-28283 [HIGH] CWE-591 CVE-2023-28283: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22039P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-22039 [HIGH] CVE-2022-22039: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2026-33826P3HIGHCVSS 8.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-33826 [HIGH] CWE-20 CVE-2026-33826: Improper input validation in Windows Active Directory allows an authorized attacker to execute code
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
nvd
CVE-2026-21236P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21236 [HIGH] CWE-122 CVE-2026-21236: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21246P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21246 [HIGH] CWE-122 CVE-2026-21246: Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26668P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-26668 [HIGH] CWE-122 CVE-2025-26668: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-59242P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.228242025-10-14
CVE-2025-59242 [HIGH] CWE-122 CVE-2025-59242: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-43467P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.221752024-09-10
CVE-2024-43467 [HIGH] CWE-362 CVE-2024-43467: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2024-38262P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-38262 [HIGH] CWE-591 CVE-2024-38262: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2026-45638P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-45638 [HIGH] CWE-122 CVE-2026-45638: Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized att
Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49184P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-49184 [HIGH] CWE-122 CVE-2026-49184: Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50482P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50482 [HIGH] CWE-122 CVE-2026-50482: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-58640P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-58640 [HIGH] CWE-122 CVE-2026-58640: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-50309P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50309 [HIGH] CWE-122 CVE-2026-50309: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2026-54987P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-54987 [HIGH] CWE-122 CVE-2026-54987: Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privil
Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.
nvd