cbcvebase.

Microsoft Windows Server 2012 R2 vulnerabilities

2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.

Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12

Vulnerabilities

Page 95 of 141
CVE-2025-26676P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.225232025-04-08
CVE-2025-26676 [MEDIUM] CWE-126 CVE-2025-26676: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-42912P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-42912 [HIGH] CWE-362 CVE-2026-42912: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32083P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-32083 [HIGH] CWE-362 CVE-2026-32083: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32082P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-32082 [HIGH] CWE-362 CVE-2026-32082: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-42836P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232282026-06-09
CVE-2026-42836 [HIGH] CWE-362 CVE-2026-42836: Concurrent execution using shared resource with improper synchronization ('race condition') in Funct Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34331P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34331 [HIGH] CWE-362 CVE-2026-34331: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-26174P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-26174 [HIGH] CWE-362 CVE-2026-26174: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33099P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-33099 [HIGH] CWE-416 CVE-2026-33099: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-33100P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-33100 [HIGH] CWE-416 CVE-2026-33100: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32068P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231322026-04-14
CVE-2026-32068 [HIGH] CWE-362 CVE-2026-32068: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54107P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-54107 [HIGH] CWE-362 CVE-2026-54107: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50321P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50321 [HIGH] CWE-362 CVE-2026-50321: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-34334P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.231812026-05-12
CVE-2026-34334 [HIGH] CWE-362 CVE-2026-34334: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-49803P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-49803 [HIGH] CWE-362 CVE-2026-49803: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50669P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50669 [HIGH] CWE-362 CVE-2026-50669: Concurrent execution using shared resource with improper synchronization ('race condition') in Windo Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-24996P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.224702025-03-11
CVE-2025-24996 [MEDIUM] CWE-73 CVE-2025-24996: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-50426P3MEDIUMCVSS 6.8≥ 6.3.9600.0, < 6.3.9600.232912026-07-14
CVE-2026-50426 [MEDIUM] CWE-23 CVE-2026-50426: Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
nvd
CVE-2025-58729P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.228242025-10-14
CVE-2025-58729 [MEDIUM] CWE-1287 CVE-2025-58729: Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an auth Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2023-35351P3MEDIUMCVSS 6.6≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35351 [MEDIUM] CWE-416 CVE-2023-35351: Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
nvd
CVE-2023-35346P3MEDIUMCVSS 6.6≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-35346 [MEDIUM] CWE-591 CVE-2023-35346: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd