cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 5 of 141
CVE-2021-31199P1HIGHCVSS 7.8KEV≥ 6.3.0, < 6.3.9600.20045≥ 6.3.0, < 6.3.9600.200442021-06-08
CVE-2021-31199 [HIGH] CVE-2021-31199: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
nvd
CVE-2021-31201P1HIGHCVSS 7.8KEV≥ 6.3.0, < 6.3.9600.20045≥ 6.3.0, < 6.3.9600.200442021-06-08
CVE-2021-31201 [HIGH] CVE-2021-31201: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
nvd
CVE-2023-36584P2MEDIUMCVSS 5.4KEV≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36584 [MEDIUM] CVE-2023-36584: Windows Mark of the Web Security Feature Bypass Vulnerability Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2023-36563P2MEDIUMCVSS 5.5KEV≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36563 [MEDIUM] CWE-20 CVE-2023-36563: Microsoft WordPad Information Disclosure Vulnerability Microsoft WordPad Information Disclosure Vulnerability
nvd
CVE-2025-24991P2MEDIUMCVSS 5.5KEV≥ 6.3.9600.0, < 6.3.9600.224702025-03-11
CVE-2025-24991 [MEDIUM] CWE-125 CVE-2025-24991: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally. Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2025-24984P2MEDIUMCVSS 4.6KEV≥ 6.3.9600.0, < 6.3.9600.224702025-03-11
CVE-2025-24984 [MEDIUM] CWE-532 CVE-2025-24984: Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2026-41089P1CRITICALCVSS 9.8ExploitedPoC≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-41089 [CRITICAL] CWE-121 CVE-2026-41089: Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
nvd
CVE-2022-26809P1CRITICALCVSS 9.8ExploitedPoCRansomware≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-26809 [CRITICAL] CVE-2022-26809: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-30136P1CRITICALCVSS 9.8ExploitedPoC≥ 6.3.9600.0, < 6.3.9600.204022022-06-15
CVE-2022-30136 [CRITICAL] CVE-2022-30136: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2022-34721P1CRITICALCVSS 9.8ExploitedPoC≥ 6.3.9600.0, < 6.3.9600.205712022-09-13
CVE-2022-34721 [CRITICAL] CVE-2022-34721: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2024-43451MEDIUMCVSS 6.5KEVPoCRansomware≥ 6.3.9600.0, < 6.3.9600.222672024-11-12
CVE-2024-43451 [MEDIUM] CWE-73 NTLM Hash Disclosure Spoofing Vulnerability NTLM Hash Disclosure Spoofing Vulnerability NTLM Hash Disclosure Spoofing Vulnerability
cvelistv5
CVE-2021-40449HIGHCVSS 7.8KEVPoCRansomware≥ 6.3.0, < 6.3.9600.201442021-10-13
CVE-2021-40449 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-36942HIGHCVSS 7.5KEVPoCRansomware≥ 6.3.0, < 6.3.9600.200942021-08-12
CVE-2021-36942 [HIGH] Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability
cvelistv5
CVE-2023-29336HIGHCVSS 7.8KEVPoC≥ 6.3.9600.0, < 6.3.9600.209692023-05-09
CVE-2023-29336 [HIGH] CWE-416 Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2019-1040P1MEDIUMCVSS 5.3ExploitedPoC≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-1040 [MEDIUM] CVE-2019-1040: A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to s A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the
nvd
CVE-2021-31956HIGHCVSS 7.8KEVPoC≥ 6.3.0, < 6.3.9600.20045≥ 6.3.0, < 6.3.9600.200442021-06-08
CVE-2021-31956 [HIGH] Windows NTFS Elevation of Privilege Vulnerability Windows NTFS Elevation of Privilege Vulnerability Windows NTFS Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-24071P1MEDIUMCVSS 6.5ExploitedPoC≥ 6.3.9600.0, < 6.3.9600.224702025-03-11
CVE-2025-24071 [MEDIUM] CWE-200 CVE-2025-24071: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-30090P1HIGHCVSS 7.0ExploitedPoCRansomware≥ 6.3.9600.0, < 6.3.9600.220232024-06-11
CVE-2024-30090 [HIGH] CWE-822 CVE-2024-30090: Microsoft Streaming Service Elevation of Privilege Vulnerability Microsoft Streaming Service Elevation of Privilege Vulnerability
nvd
CVE-2022-24481P2HIGHCVSS 7.8ExploitedPoC≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-24481 [HIGH] CVE-2022-24481: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-26229P1HIGHCVSS 7.8ExploitedPoC≥ 6.3.9600.0, < 6.3.9600.219242024-04-09
CVE-2024-26229 [HIGH] CWE-122 CVE-2024-26229: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase