Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 45 of 141
CVE-2023-21546P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21546 [HIGH] CWE-591 CVE-2023-21546: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2023-21679P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21679 [HIGH] CWE-416 CVE-2023-21679: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2023-21555P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21555 [HIGH] CWE-367 CVE-2023-21555: Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability
nvd
CVE-2023-21548P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21548 [HIGH] CWE-591 CVE-2023-21548: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2023-21535P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.207782023-01-10
CVE-2023-21535 [HIGH] CWE-591 CVE-2023-21535: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-44676P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.207212022-12-13
CVE-2022-44676 [HIGH] CWE-362 CVE-2022-44676: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2022-41039P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.206712022-11-09
CVE-2022-41039 [HIGH] CWE-362 CVE-2022-41039: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-23405P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-23405 [HIGH] CWE-190 CVE-2023-23405: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24908P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-24908 [HIGH] CWE-190 CVE-2023-24908: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-24869P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-24869 [HIGH] CWE-190 CVE-2023-24869: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2023-21712P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.206712023-04-27
CVE-2023-21712 [HIGH] CWE-362 CVE-2023-21712: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2022-41088P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.206712022-11-09
CVE-2022-41088 [HIGH] CWE-362 CVE-2022-41088: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-24903P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.209692023-05-09
CVE-2023-24903 [HIGH] CWE-415 CVE-2023-24903: Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
nvd
CVE-2018-8493P3HIGHCVSS 7.5v(Server Core installation)2018-10-10
CVE-2018-8493 [HIGH] CVE-2018-8493: An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles frag
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka "Windows TCP/IP Information Disclosure Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2023-23404P3HIGHCVSS 8.1≥ 6.3.9600.0, < 6.3.9600.208652023-03-14
CVE-2023-23404 [HIGH] CWE-416 CVE-2023-23404: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2026-27912P3HIGHCVSS 8.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-27912 [HIGH] CWE-285 CVE-2026-27912: Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2025-53149P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.227252025-08-12
CVE-2025-53149 [HIGH] CWE-122 CVE-2025-53149: Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacke
Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24063P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.225772025-05-13
CVE-2025-24063 [HIGH] CWE-122 CVE-2025-24063: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges loc
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60714P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.228692025-11-11
CVE-2025-60714 [HIGH] CWE-122 CVE-2025-60714: Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-35632P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.217152023-12-12
CVE-2023-35632 [HIGH] CWE-190 CVE-2023-35632: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd