Msrc Windows Server 2012 R2 vulnerabilities
3,441 known vulnerabilities affecting msrc/windows_server_2012_r2.
Total CVEs
3,441
CISA KEV
141
actively exploited
Public exploits
207
Exploited in wild
131
Severity breakdown
CRITICAL86HIGH2272MEDIUM1047LOW36
Vulnerabilities
Page 37 of 173
CVE-2024-38196HIGHCVSS 7.82024-08-13
CVE-2024-38196 [HIGH] CWE-20 Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows listed in the Securi
msrc
CVE-2024-37968HIGHCVSS 7.52024-08-13
CVE-2024-37968 [HIGH] CWE-345 Windows DNS Spoofing Vulnerability
Windows DNS Spoofing Vulnerability
Microsoft Windows DNS: Microsoft Windows DNS
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5041578
Reference: https://support.microsoft.com/help/5041578
Reference: https://catalog.update.microsoft.c
msrc
CVE-2024-38151MEDIUMCVSS 5.52024-08-13
CVE-2024-38151 [MEDIUM] CWE-125 Windows Kernel Information Disclosure Vulnerability
Windows Kernel Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is a small amount of kernel memory which could be leaked back to the attacker.
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Wi
msrc
CVE-2024-38122MEDIUMCVSS 5.52024-08-13
CVE-2024-38122 [MEDIUM] CWE-908 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of stack memory.
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows
msrc
CVE-2024-38214MEDIUMCVSS 6.52024-08-13
CVE-2024-38214 [MEDIUM] CWE-125 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to major loss of confidentiality (C:H) but have no effect on integrity (I:N) or on availability (A:N). What does that mean for this vulnerability?
An attacker who successfully exploited the vulnerabilit
msrc
CVE-2024-38223MEDIUMCVSS 6.82024-08-13
CVE-2024-38223 [MEDIUM] CWE-284 Windows Initial Machine Configuration Elevation of Privilege Vulnerability
Windows Initial Machine Configuration Elevation of Privilege Vulnerability
FAQ: According to the CVSS metric, the attack vector is physical (AV:P). What does that mean for this vulnerability?
To exploit this vulnerability, an attacker needs physical access to the victim's machine.
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacker can use a specially crafte
msrc
CVE-2024-38118MEDIUMCVSS 5.52024-08-13
CVE-2024-38118 [MEDIUM] CWE-908 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of stack memory.
FAQ: Windows 11, version 24H2 is not generally available yet. Why are there updates for this version of Windows
msrc
CVE-2024-38213MEDIUMCVSS 6.5KEV2024-08-13
CVE-2024-38213 [MEDIUM] CWE-693 Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send
msrc
CVE-2024-38077CRITICALCVSS 9.82024-07-09
CVE-2024-38077 [CRITICAL] CWE-122 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
FAQ: How would an attacker exploit this vulnerability?
An unauthenticated attacker could connect to the Remote Desktop Licensing Service and send a malicious message which could allow remote code execution.
Windows Remote Desktop Licensing Service: Windows Remote Desktop Licensing Service
Microsoft: Microsof
msrc
CVE-2024-38074CRITICALCVSS 9.82024-07-09
CVE-2024-38074 [CRITICAL] CWE-191 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An attacker could send a specially crafted packet to a server set up as a Remote Desktop Licensing server, which will cause remote code execution.
Windows Remote Desktop Licensing Service: Windows Remote Desktop Licensing Service
Microsoft: Microsoft
Cu
msrc
CVE-2024-38034HIGHCVSS 7.82024-07-09
CVE-2024-38034 [HIGH] CWE-190 Windows Filtering Platform Elevation of Privilege Vulnerability
Windows Filtering Platform Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain administrator privileges.
Windows Filtering: Windows Filtering
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly
msrc
CVE-2024-38073HIGHCVSS 7.52024-07-09
CVE-2024-38073 [HIGH] CWE-125 Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of availability (A:H)? What does that mean for this vulnerability?
An attacker could impact availability of the service resulting in Denial of Service (DoS).
Windows Remote Desktop Licensing Service: Windows Remote D
msrc
CVE-2024-38085HIGHCVSS 7.82024-07-09
CVE-2024-38085 [HIGH] CWE-416 Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Win32 Kernel Subsystem: Windows Win32 Kernel Subsystem
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Expl
msrc
CVE-2024-38053HIGHCVSS 8.82024-07-09
CVE-2024-38053 [HIGH] CWE-416 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability
FAQ: According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?
This attack is limited to systems connected to the same network segment as the attacker. The attack cannot be performed across multiple networks (for example, a WAN) and would be limited to systems on the
msrc
CVE-2024-37988HIGHCVSS 8.02024-07-09
CVE-2024-37988 [HIGH] CWE-130 Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
An unauthenticated attacker with LAN access could exploit this vuln
msrc
CVE-2024-38071HIGHCVSS 7.52024-07-09
CVE-2024-38071 [HIGH] CWE-126 Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of availability (A:H)? What does that mean for this vulnerability?
An attacker could impact availability of the service resulting in Denial of Service (DoS).
Windows Remote Desktop Licensing Service: Windows Remote D
msrc
CVE-2024-37987HIGHCVSS 8.02024-07-09
CVE-2024-37987 [HIGH] CWE-843 Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass Secure Boot.
FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability?
An unauthenticated attacker with LAN access could exploit this vuln
msrc
CVE-2024-30079HIGHCVSS 7.82024-07-09
CVE-2024-30079 [HIGH] CWE-126 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows Remote Access Connection Manager: Windows Remote Access Connection Manager
Microsoft: Microsoft
Customer Action Req
msrc
CVE-2024-38057HIGHCVSS 7.82024-07-09
CVE-2024-38057 [HIGH] CWE-125 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Microsoft Streaming Service: Microsoft Streaming Service
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elev
msrc
CVE-2024-38070HIGHCVSS 7.82024-07-09
CVE-2024-38070 [HIGH] CWE-693 Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the execution policy for the Windows LockDown Policy (WLDP) for the WDAC API.
Windows LockDown Policy (WLDP): Windows LockDown Policy (WLDP)
Microsoft: Micros
msrc