cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 64 of 141
CVE-2024-26234MEDIUMCVSS 6.7Exploited≥ 6.3.9600.0, < 6.3.9600.219242024-04-09
CVE-2024-26234 [MEDIUM] CWE-284 Proxy Driver Spoofing Vulnerability Proxy Driver Spoofing Vulnerability Proxy Driver Spoofing Vulnerability
cvelistv5
CVE-2024-38198P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.221342024-08-13
CVE-2024-38198 [HIGH] CWE-345 CVE-2024-38198: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2024-43456P3HIGHCVSS 7.4≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-43456 [HIGH] CWE-284 CVE-2024-43456: Windows Remote Desktop Services Tampering Vulnerability Windows Remote Desktop Services Tampering Vulnerability
nvd
CVE-2026-35416P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-35416 [HIGH] CWE-416 CVE-2026-35416: Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver f Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-33163P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33163 [HIGH] CWE-591 CVE-2023-33163: Windows Network Load Balancing Remote Code Execution Vulnerability Windows Network Load Balancing Remote Code Execution Vulnerability
nvd
CVE-2025-62213P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.228692025-11-11
CVE-2025-62213 [HIGH] CWE-416 CVE-2025-62213: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-21235P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.230222026-02-10
CVE-2026-21235 [HIGH] CWE-416 CVE-2026-21235: Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges l Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54911P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-54911 [HIGH] CWE-416 CVE-2025-54911: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2021-26435P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.201202021-09-15
CVE-2021-26435 [HIGH] CWE-787 CVE-2021-26435: Windows Scripting Engine Memory Corruption Vulnerability Windows Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2019-0908P3HIGHCVSS 7.8≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0908 [HIGH] CVE-2019-0908: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2019-1157P3HIGHCVSS 7.8≥ 6.3.0, < publication2019-08-14
CVE-2019-1157 [HIGH] CWE-94 CVE-2019-1157: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vuln
nvd
CVE-2019-1146P3HIGHCVSS 7.8≥ 6.3.0, < publication2019-08-14
CVE-2019-1146 [HIGH] CVE-2019-1146: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2019-1156P3HIGHCVSS 7.8≥ 6.3.0, < publication2019-08-14
CVE-2019-1156 [HIGH] CVE-2019-1156: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2019-1147P3HIGHCVSS 7.8≥ 6.3.0, < publication2019-08-14
CVE-2019-1147 [HIGH] CVE-2019-1147: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2019-1155P3HIGHCVSS 7.8≥ 6.3.0, < publication2019-08-14
CVE-2019-1155 [HIGH] CVE-2019-1155: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2020-1039P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-09-11
CVE-2020-1039 [HIGH] CVE-2020-1039: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2020-1558P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-08-17
CVE-2020-1558 [HIGH] CVE-2020-1558: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2020-16924P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-10-16
CVE-2020-16924 [HIGH] CVE-2020-16924: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabi
nvd
CVE-2019-0907P3HIGHCVSS 7.8≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0907 [HIGH] CVE-2019-0907: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
CVE-2019-0904P3HIGHCVSS 7.8≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0904 [HIGH] CVE-2019-0904: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerabili
nvd
Microsoft Windows Server 2012 R2 vulnerabilities | cvebase