cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 44 of 141
CVE-2026-0386P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.229682026-01-13
CVE-2026-0386 [HIGH] CWE-284 CVE-2026-0386: Improper access control in Windows Deployment Services allows an unauthorized attacker to execute co Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-60704P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.228692025-11-11
CVE-2025-60704 [HIGH] CWE-325 CVE-2025-60704: Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2021-31971P3HIGHCVSS 8.8≥ 6.3.0, < 6.3.9600.20045≥ 6.3.0, < 1.0.0.02021-06-08
CVE-2021-31971 [HIGH] CVE-2021-31971: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2020-1031P3HIGHCVSS 7.5≥ 6.3.0, < publication2020-09-11
CVE-2020-1031 [HIGH] CVE-2020-1031: <p>An information disclosure vulnerability exists in the way that the Windows Server DHCP service im An information disclosure vulnerability exists in the way that the Windows Server DHCP service improperly discloses the contents of its memory. To exploit the vulnerability, an unauthenticated attacker could send a specially crafted packet to an affected DHCP server. An attacker who successfully exploited this vulnerability could obtain information to further c
nvd
CVE-2024-43623P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.222672024-11-12
CVE-2024-43623 [HIGH] CWE-190 CVE-2024-43623: Windows NT OS Kernel Elevation of Privilege Vulnerability Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2021-34446P3HIGHCVSS 8.8≥ 6.3.0, < 6.3.9600.20069≥ 6.3.0, < 1.0012021-07-16
CVE-2021-34446 [HIGH] CVE-2021-34446: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2024-38124P3CRITICALCVSS 9.0≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-38124 [CRITICAL] CWE-287 CVE-2024-38124: Windows Netlogon Elevation of Privilege Vulnerability Windows Netlogon Elevation of Privilege Vulnerability
nvd
CVE-2024-26211P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.219722024-04-09
CVE-2024-26211 [HIGH] CWE-122 CVE-2024-26211: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2022-37975P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-37975 [HIGH] CVE-2022-37975: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-24542P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-24542 [HIGH] CVE-2022-24542: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2024-49105P3HIGHCVSS 8.4≥ 6.3.9600.0, < 6.3.9600.223182024-12-12
CVE-2024-49105 [HIGH] CWE-284 CVE-2024-49105: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2022-35830P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.205712022-09-13
CVE-2022-35830 [HIGH] CVE-2022-35830: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-35767P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.205202022-08-09
CVE-2022-35767 [HIGH] CWE-94 CVE-2022-35767: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-41081P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-41081 [HIGH] CVE-2022-41081: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-26812P3HIGHCVSS 7.2≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-26812 [HIGH] CVE-2022-26812: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-24536P3HIGHCVSS 7.2≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-24536 [HIGH] CVE-2022-24536: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26815P3HIGHCVSS 7.2≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-26815 [HIGH] CVE-2022-26815: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-26813P3HIGHCVSS 7.2≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-26813 [HIGH] CVE-2022-26813: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2022-38000P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-38000 [HIGH] CWE-362 CVE-2022-38000: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-22035P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.206252022-10-11
CVE-2022-22035 [HIGH] CWE-362 CVE-2022-22035: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase