Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 87 of 141
CVE-2023-36574P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36574 [HIGH] CWE-94 CVE-2023-36574: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36571P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36571 [HIGH] CWE-94 CVE-2023-36571: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36573P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36573 [HIGH] CWE-94 CVE-2023-36573: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36589P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36589 [HIGH] CWE-94 CVE-2023-36589: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36570P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36570 [HIGH] CWE-94 CVE-2023-36570: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36575P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36575 [HIGH] CWE-94 CVE-2023-36575: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36572P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36572 [HIGH] CWE-94 CVE-2023-36572: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2023-36591P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36591 [HIGH] CWE-94 CVE-2023-36591: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2024-26216P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.219242024-04-09
CVE-2024-26216 [HIGH] CWE-59 CVE-2024-26216: Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2021-28439P3HIGHCVSS 7.5≥ 6.3.0, < publication2021-04-13
CVE-2021-28439 [HIGH] CVE-2021-28439: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2026-32093P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-32093 [HIGH] CWE-122 CVE-2026-32093: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-24285P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.230742026-03-10
CVE-2026-24285 [HIGH] CWE-416 CVE-2026-24285: Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53140P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.227252025-08-12
CVE-2025-53140 [HIGH] CWE-416 CVE-2025-53140: Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges loc
Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32073P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-32073 [HIGH] CWE-416 CVE-2026-32073: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32075P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-32075 [HIGH] CWE-416 CVE-2026-32075: Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker t
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34347P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34347 [HIGH] CWE-416 CVE-2026-34347: Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-58629P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-58629 [HIGH] CWE-416 CVE-2026-58629: Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50397P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50397 [HIGH] CWE-416 CVE-2026-50397: Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-1577P3MEDIUMCVSS 6.5≥ 6.3.0, < publication2020-08-17
CVE-2020-1577 [MEDIUM] CVE-2020-1577: An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted
nvd
CVE-2025-59185P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.228242025-10-14
CVE-2025-59185 [MEDIUM] CWE-73 CVE-2025-59185: External control of file name or path in Windows Core Shell allows an unauthorized attacker to perfo
External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network.
nvd