cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 62 of 141
CVE-2020-0790P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-09-11
CVE-2020-0790 [HIGH] CVE-2020-0790: <p>A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if th
nvd
CVE-2024-26173P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.218712024-03-12
CVE-2024-26173 [HIGH] CWE-20 CVE-2024-26173: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26178P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.218712024-03-12
CVE-2024-26178 [HIGH] CWE-122 CVE-2024-26178: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-21180P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.224702025-03-11
CVE-2025-21180 [HIGH] CWE-122 CVE-2025-21180: Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.
nvd
CVE-2019-1028P3HIGHCVSS 7.8≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-1028 [HIGH] CVE-2019-1028: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
CVE-2025-32724P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.226202025-06-10
CVE-2025-32724 [HIGH] CWE-400 CVE-2025-32724: Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allo Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-26176P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.218712024-03-12
CVE-2024-26176 [HIGH] CWE-126 CVE-2024-26176: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38070P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38070 [HIGH] CWE-693 CVE-2024-38070: Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
nvd
CVE-2023-36701P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36701 [HIGH] CWE-125 CVE-2023-36701: Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability Microsoft Resilient File System (ReFS) Elevation of Privilege Vulnerability
nvd
CVE-2024-30079P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-30079 [HIGH] CWE-126 CVE-2024-30079: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
nvd
CVE-2024-43501P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-43501 [HIGH] CWE-59 CVE-2024-43501: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-21359P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.224172025-02-11
CVE-2025-21359 [HIGH] CWE-284 CVE-2025-21359: Windows Kernel Security Feature Bypass Vulnerability Windows Kernel Security Feature Bypass Vulnerability
nvd
CVE-2026-48575P3HIGHCVSS 7.9≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-48575 [HIGH] CWE-693 CVE-2026-48575: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48570P3HIGHCVSS 7.9≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-48570 [HIGH] CWE-693 CVE-2026-48570: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48568P3HIGHCVSS 7.9≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-48568 [HIGH] CWE-693 CVE-2026-48568: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-45588P3HIGHCVSS 7.9≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-45588 [HIGH] CWE-693 CVE-2026-45588: Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a securi Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2026-48578P3HIGHCVSS 7.9≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-48578 [HIGH] CWE-284 CVE-2026-48578: Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges l Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38153P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.221342024-08-13
CVE-2024-38153 [HIGH] CWE-367 CVE-2024-38153: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-38191P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.220742024-08-13
CVE-2024-38191 [HIGH] CWE-362 CVE-2024-38191: Kernel Streaming Service Driver Elevation of Privilege Vulnerability Kernel Streaming Service Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-24059P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.224702025-03-11
CVE-2025-24059 [HIGH] CWE-125 CVE-2025-24059: Incorrect conversion between numeric types in Windows Common Log File System Driver allows an author Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd