cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 61 of 141
CVE-2023-35387P3HIGHCVSS 8.8≥ 6.3.9600.0, < 6.3.9600.215032023-08-08
CVE-2023-35387 [HIGH] CWE-191 CVE-2023-35387: Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability Windows Bluetooth A2DP driver Elevation of Privilege Vulnerability
nvd
CVE-2021-1668P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-01-12
CVE-2021-1668 [HIGH] CVE-2021-1668: Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability Microsoft DTV-DVD Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2023-38162P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.215632023-09-12
CVE-2023-38162 [HIGH] CWE-191 CVE-2023-38162: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2021-26415P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-04-13
CVE-2021-26415 [HIGH] CWE-20 CVE-2021-26415: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2020-1466P3HIGHCVSS 7.5≥ 6.3.0, < publication2020-08-17
CVE-2020-1466 [HIGH] CVE-2020-1466: A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an atta A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RD Gateway service on the target system to stop responding. To exploit this vulnerability, an attacker wou
nvd
CVE-2021-26868P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-03-11
CVE-2021-26868 [HIGH] CWE-119 CVE-2021-26868: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-21371P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.218132024-02-13
CVE-2024-21371 [HIGH] CWE-367 CVE-2024-21371: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-29115P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.203712022-05-10
CVE-2022-29115 [HIGH] CVE-2022-29115: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2021-27089P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-04-13
CVE-2021-27089 [HIGH] CVE-2021-27089: Microsoft Internet Messaging API Remote Code Execution Vulnerability Microsoft Internet Messaging API Remote Code Execution Vulnerability
nvd
CVE-2018-8335P3HIGHCVSS 7.5v(Server Core installation)2018-09-13
CVE-2018-8335 [HIGH] CVE-2018-8335: A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacke A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
nvd
CVE-2022-21913P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.202462022-01-11
CVE-2022-21913 [HIGH] CVE-2022-21913: Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
nvd
CVE-2022-22027P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-22027 [HIGH] CVE-2022-22027: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-22024P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-22024 [HIGH] CVE-2022-22024: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2023-35317P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35317 [HIGH] CWE-502 CVE-2023-35317: Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
nvd
CVE-2026-23668P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.230742026-03-10
CVE-2026-23668 [HIGH] CWE-362 CVE-2026-23668: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49805P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-49805 [HIGH] CWE-284 CVE-2026-49805: Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locall Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-27473P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-27473 [HIGH] CWE-400 CVE-2025-27473: Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny servic Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
nvd
CVE-2022-30164P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.204022022-06-15
CVE-2022-30164 [HIGH] CVE-2022-30164: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
nvd
CVE-2024-49090P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.223182024-12-12
CVE-2024-49090 [HIGH] CWE-822 CVE-2024-49090: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-49088P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.223182024-12-12
CVE-2024-49088 [HIGH] CWE-126 CVE-2024-49088: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase