cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 93 of 141
CVE-2025-53797P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-53797 [MEDIUM] CWE-126 CVE-2025-53797: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-53796P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.227742025-09-09
CVE-2025-53796 [MEDIUM] CWE-126 CVE-2025-53796: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-58739P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.228242025-10-14
CVE-2025-58739 [MEDIUM] CWE-200 CVE-2025-58739: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-50366P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50366 [MEDIUM] CWE-476 CVE-2026-50366: Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny s Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
nvd
CVE-2026-57976P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-57976 [MEDIUM] CWE-476 CVE-2026-57976: Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny s Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
nvd
CVE-2026-55003P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-55003 [MEDIUM] CWE-908 CVE-2026-55003: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58546P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-58546 [MEDIUM] CWE-908 CVE-2026-58546: Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2022-26831P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.203372022-04-15
CVE-2022-26831 [HIGH] CVE-2022-26831: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2024-49096P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.223182024-12-12
CVE-2024-49096 [HIGH] CWE-400 CVE-2024-49096: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21230P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21230 [HIGH] CWE-20 CVE-2025-21230: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21251P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21251 [HIGH] CWE-400 CVE-2025-21251: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2024-38132P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.221342024-08-13
CVE-2024-38132 [HIGH] CWE-125 CVE-2024-38132: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2024-38073P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38073 [HIGH] CWE-125 CVE-2024-38073: Windows Remote Desktop Licensing Service Denial of Service Vulnerability Windows Remote Desktop Licensing Service Denial of Service Vulnerability
nvd
CVE-2023-36392P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.216682023-11-14
CVE-2023-36392 [HIGH] CWE-126 CVE-2023-36392: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2024-38230P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.221752024-09-10
CVE-2024-38230 [HIGH] CWE-20 CVE-2024-38230: Windows Standards-Based Storage Management Service Denial of Service Vulnerability Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd
CVE-2023-36703P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36703 [HIGH] CWE-400 CVE-2023-36703: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2025-21289P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21289 [HIGH] CWE-400 CVE-2025-21289: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21290P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21290 [HIGH] CWE-400 CVE-2025-21290: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21270P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21270 [HIGH] CWE-400 CVE-2025-21270: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2024-38091P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.220742024-07-09
CVE-2024-38091 [HIGH] CWE-166 CVE-2024-38091: Microsoft WS-Discovery Denial of Service Vulnerability Microsoft WS-Discovery Denial of Service Vulnerability
nvd