Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 77 of 141
CVE-2021-40478P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.201442021-10-13
CVE-2021-40478 [HIGH] CWE-269 CVE-2021-40478: Storage Spaces Controller Elevation of Privilege Vulnerability
Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2021-41345P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.201442021-10-13
CVE-2021-41345 [HIGH] CWE-269 CVE-2021-41345: Storage Spaces Controller Elevation of Privilege Vulnerability
Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2020-1538P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-08-17
CVE-2020-1538 [HIGH] CVE-2020-1538: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles
An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting how the Wind
nvd
CVE-2020-1517P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-08-17
CVE-2020-1517 [HIGH] CVE-2020-1517: An elevation of privilege vulnerability exists when the Windows File Server Resource Management Serv
An elevation of privilege vulnerability exists when the Windows File Server Resource Management Service improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by
nvd
CVE-2020-1488P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-08-17
CVE-2020-1488 [HIGH] CWE-269 CVE-2020-1488: An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperl
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by corr
nvd
CVE-2020-0912P3HIGHCVSS 7.8≥ 6.3.0, < publication2020-09-11
CVE-2020-0912 [HIGH] CVE-2020-0912: <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider
An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correct
nvd
CVE-2023-21817P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-21817 [HIGH] CWE-287 CVE-2023-21817: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2021-1652P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-01-12
CVE-2021-1652 [HIGH] CWE-269 CVE-2021-1652: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1653P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-01-12
CVE-2021-1653 [HIGH] CWE-269 CVE-2021-1653: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1693P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-01-12
CVE-2021-1693 [HIGH] CWE-269 CVE-2021-1693: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1654P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-01-12
CVE-2021-1654 [HIGH] CWE-269 CVE-2021-1654: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1655P3HIGHCVSS 7.8≥ 6.3.0, < publication2021-01-12
CVE-2021-1655 [HIGH] CWE-269 CVE-2021-1655: Windows CSC Service Elevation of Privilege Vulnerability
Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21822P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-21822 [HIGH] CWE-416 CVE-2023-21822: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-36726P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36726 [HIGH] CWE-416 CVE-2023-36726: Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
nvd
CVE-2023-21805P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-21805 [HIGH] CWE-77 CVE-2023-21805: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2023-29367P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.210132023-06-14
CVE-2023-29367 [HIGH] CWE-908 CVE-2023-29367: iSCSI Target WMI Provider Remote Code Execution Vulnerability
iSCSI Target WMI Provider Remote Code Execution Vulnerability
nvd
CVE-2025-27733P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-27733 [HIGH] CWE-125 CVE-2025-27733: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-21691P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.208212023-02-14
CVE-2023-21691 [HIGH] CWE-125 CVE-2023-21691: Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability
Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability
nvd
CVE-2021-34514P3HIGHCVSS 7.8≥ 6.3.0, < 6.3.9600.200692021-07-14
CVE-2021-34514 [HIGH] CWE-269 CVE-2021-34514: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-36711P3HIGHCVSS 7.8≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36711 [HIGH] CWE-59 CVE-2023-36711: Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
nvd