Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 58 of 141
CVE-2020-1467P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-08-17
CVE-2020-1467 [HIGH] CVE-2020-1467: An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attack
An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that co
nvd
CVE-2022-21989P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.202692022-02-09
CVE-2022-21989 [HIGH] CVE-2022-21989: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-37967P3HIGHCVSS 7.2≥ 6.3.9600.0, < 6.3.9600.216202022-11-09
CVE-2022-37967 [HIGH] CVE-2022-37967: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2019-0909P3HIGHCVSS 7.5≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0909 [HIGH] CVE-2019-0909: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2026-50507P3MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-50507 [MEDIUM] CWE-306 CVE-2026-50507: Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
nvd
CVE-2020-16939P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-10-16
CVE-2020-16939 [HIGH] CWE-59 CVE-2020-16939: <p>An elevation of privilege vulnerability exists when Group Policy improperly checks access. An att
An elevation of privilege vulnerability exists when Group Policy improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affecte
nvd
CVE-2024-49019P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.222672024-11-12
CVE-2024-49019 [HIGH] CWE-1390 CVE-2024-49019: Active Directory Certificate Services Elevation of Privilege Vulnerability
Active Directory Certificate Services Elevation of Privilege Vulnerability
nvd
CVE-2022-35793P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.205202022-08-09
CVE-2022-35793 [HIGH] CVE-2022-35793: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-26931P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.203712022-05-10
CVE-2022-26931 [HIGH] CVE-2022-26931: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2024-38127P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.221342024-08-13
CVE-2024-38127 [HIGH] CWE-126 CVE-2024-38127: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2021-28315P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-04-13
CVE-2021-28315 [HIGH] CVE-2021-28315: Windows Media Video Decoder Remote Code Execution Vulnerability
Windows Media Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2022-30209P3HIGHCVSS 7.4≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-30209 [HIGH] CVE-2022-30209: Windows IIS Server Elevation of Privilege Vulnerability
Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2025-27470P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-27470 [HIGH] CWE-400 CVE-2025-27470: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26652P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-26652 [HIGH] CWE-400 CVE-2025-26652: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27479P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-27479 [HIGH] CWE-410 CVE-2025-27479: Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over
Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21174P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-21174 [HIGH] CWE-400 CVE-2025-21174: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27486P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-27486 [HIGH] CWE-400 CVE-2025-27486: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27485P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-27485 [HIGH] CWE-400 CVE-2025-27485: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26680P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-26680 [HIGH] CWE-400 CVE-2025-26680: Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an un
Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-38245P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.221752024-09-10
CVE-2024-38245 [HIGH] CWE-20 CVE-2024-38245: Kernel Streaming Service Driver Elevation of Privilege Vulnerability
Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd