Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 65 of 141
CVE-2019-0905P3HIGHCVSS 7.8≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0905 [HIGH] CVE-2019-0905: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-0974P3HIGHCVSS 7.8≥ 6.3.9600.0, < publication2019-06-12
CVE-2019-0974 [HIGH] CVE-2019-0974: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2020-1564P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-08-17
CVE-2020-1564 [HIGH] CVE-2020-1564: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2020-1557P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-08-17
CVE-2020-1557 [HIGH] CVE-2020-1557: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2021-34504P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.200692021-07-14
CVE-2021-34504 [HIGH] CVE-2021-34504: Windows Address Book Remote Code Execution Vulnerability
Windows Address Book Remote Code Execution Vulnerability
nvd
CVE-2022-26926P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.203712022-05-10
CVE-2022-26926 [HIGH] CWE-284 CVE-2022-26926: Windows Address Book Remote Code Execution Vulnerability
Windows Address Book Remote Code Execution Vulnerability
nvd
CVE-2022-26903P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-26903 [HIGH] CVE-2022-26903: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2020-1565P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-08-17
CVE-2020-1565 [HIGH] CVE-2020-1565: An elevation of privilege vulnerability exists when the "Public Account Pictures" folder i
An elevation of privilege vulnerability exists when the "Public Account Pictures" folder improperly handles junctions.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting
nvd
CVE-2021-26861P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-03-11
CVE-2021-26861 [HIGH] CVE-2021-26861: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2022-30206P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-30206 [HIGH] CVE-2022-30206: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-36937P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.200942021-08-12
CVE-2021-36937 [HIGH] CVE-2021-36937: Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2021-43234P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.202072021-12-15
CVE-2021-43234 [HIGH] CVE-2021-43234: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-37955P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.205712022-09-13
CVE-2022-37955 [HIGH] CVE-2022-37955: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2021-41331P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.201442021-10-13
CVE-2021-41331 [HIGH] CVE-2021-41331: Windows Media Audio Decoder Remote Code Execution Vulnerability
Windows Media Audio Decoder Remote Code Execution Vulnerability
nvd
CVE-2021-41340P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.201442021-10-13
CVE-2021-41340 [HIGH] CVE-2021-41340: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2022-24494P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-24494 [HIGH] CVE-2022-24494: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-23284P3HIGHCVSS 7.2≥ 6.3.9600.0, < 6.3.9600.203032022-03-09
CVE-2022-23284 [HIGH] CVE-2022-23284: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-21838P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.202462022-01-11
CVE-2022-21838 [HIGH] CWE-59 CVE-2022-21838: Windows Cleanup Manager Elevation of Privilege Vulnerability
Windows Cleanup Manager Elevation of Privilege Vulnerability
nvd
CVE-2024-38064P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38064 [HIGH] CWE-908 CVE-2024-38064: Windows TCP/IP Information Disclosure Vulnerability
Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2023-41766P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-41766 [HIGH] CWE-426 CVE-2023-41766: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd