Microsoft Windows Server 2012 R2 vulnerabilities
2,812 known vulnerabilities affecting microsoft/windows_server_2012_r2.
Total CVEs
2,812
CISA KEV
97
actively exploited
Public exploits
93
Exploited in wild
129
Severity breakdown
CRITICAL105HIGH1991MEDIUM704LOW12
Vulnerabilities
Page 97 of 141
CVE-2023-36581P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.216202023-10-10
CVE-2023-36581 [HIGH] CWE-126 CVE-2023-36581: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21276P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.223712025-01-14
CVE-2025-21276 [HIGH] CWE-191 CVE-2025-21276: Windows MapUrlToZone Denial of Service Vulnerability
Windows MapUrlToZone Denial of Service Vulnerability
nvd
CVE-2024-43512P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.222212024-10-08
CVE-2024-43512 [HIGH] CWE-835 CVE-2024-43512: Windows Standards-Based Storage Management Service Denial of Service Vulnerability
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
nvd
CVE-2020-1256P3MEDIUMCVSS 6.5≥ 6.3.0, < publication2020-09-11
CVE-2020-1256 [MEDIUM] CVE-2020-1256: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2023-24942P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.209692023-05-09
CVE-2023-24942 [HIGH] CWE-126 CVE-2023-24942: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33173P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33173 [HIGH] CWE-126 CVE-2023-33173: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33172P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33172 [HIGH] CWE-126 CVE-2023-33172: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33168P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33168 [HIGH] CWE-126 CVE-2023-33168: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33167P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33167 [HIGH] CWE-126 CVE-2023-33167: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33166P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33166 [HIGH] CWE-126 CVE-2023-33166: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-32034P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-32034 [HIGH] CWE-125 CVE-2023-32034: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-32035P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-32035 [HIGH] CWE-125 CVE-2023-32035: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2023-33169P3HIGHCVSS 7.5≥ 6.3.9600.0, < 6.3.9600.210632023-07-11
CVE-2023-33169 [HIGH] CWE-126 CVE-2023-33169: Remote Procedure Call Runtime Denial of Service Vulnerability
Remote Procedure Call Runtime Denial of Service Vulnerability
nvd
CVE-2022-22040P3HIGHCVSS 7.3≥ 6.3.9600.0, < 6.3.9600.204782022-07-12
CVE-2022-22040 [HIGH] CVE-2022-22040: Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
Internet Information Services Dynamic Compression Module Denial of Service Vulnerability
nvd
CVE-2023-24948P3HIGHCVSS 7.4≥ 6.3.9600.0, < 6.3.9600.209692023-05-09
CVE-2023-24948 [HIGH] CWE-122 CVE-2023-24948: Windows Bluetooth Driver Elevation of Privilege Vulnerability
Windows Bluetooth Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-59208P3HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.228242025-10-14
CVE-2025-59208 [HIGH] CWE-125 CVE-2025-59208: Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information o
Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-59282P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.228242025-10-14
CVE-2025-59282 [HIGH] CWE-362 CVE-2025-59282: Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-48819P3HIGHCVSS 7.1≥ 6.3.9600.0, < 6.3.9600.226762025-07-08
CVE-2025-48819 [HIGH] CWE-591 CVE-2025-48819: Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
nvd
CVE-2024-26226P3MEDIUMCVSS 6.5≥ 6.3.9600.0, < 6.3.9600.219242024-04-09
CVE-2024-26226 [MEDIUM] CWE-125 CVE-2024-26226: Windows Distributed File System (DFS) Information Disclosure Vulnerability
Windows Distributed File System (DFS) Information Disclosure Vulnerability
nvd
CVE-2025-58735P3HIGHCVSS 7.0≥ 6.3.9600.0, < 6.3.9600.228242025-10-14
CVE-2025-58735 [HIGH] CWE-416 CVE-2025-58735: Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
nvd