Msrc Windows Server 2012 R2 vulnerabilities

3,441 known vulnerabilities affecting msrc/windows_server_2012_r2.

Total CVEs
3,441
CISA KEV
141
actively exploited
Public exploits
207
Exploited in wild
131
Severity breakdown
CRITICAL86HIGH2272MEDIUM1047LOW36

Vulnerabilities

Page 60 of 173
CVE-2023-35346MEDIUMCVSS 6.62023-07-11
CVE-2023-35346 [MEDIUM] CWE-591 Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition. FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability? Successful exploitation of this
msrc
CVE-2023-32042MEDIUMCVSS 6.52023-07-11
CVE-2023-32042 [MEDIUM] CWE-908 OLE Automation Information Disclosure Vulnerability OLE Automation Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory. Windows OLE: Windows OLE Microsoft: Microsoft Customer Action Required: Yes Impact: Information Disclosure Exploit Status: Publicly Disclosed:No;Exploited:N
msrc
CVE-2023-35351MEDIUMCVSS 6.62023-07-11
CVE-2023-35351 [MEDIUM] CWE-416 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An attacker with Certificate Authority (CA) read access permissions can send a specially crafted request to a vulnerable Certificate Server. By default, only domain administrators are granted CA read access. FAQ: According to the C
msrc
CVE-2023-35319MEDIUMCVSS 6.52023-07-11
CVE-2023-35319 [MEDIUM] CWE-125 Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability Windows Remote Procedure Call: Windows Remote Procedure Call Microsoft: Microsoft Customer Action Required: Yes Impact: Denial of Service Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168 Reference:
msrc
CVE-2023-35344MEDIUMCVSS 6.62023-07-11
CVE-2023-35344 [MEDIUM] CWE-591 Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to win a race condition. FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability? Successful exploitation of this
msrc
CVE-2023-35331MEDIUMCVSS 6.52023-07-11
CVE-2023-35331 [MEDIUM] Windows Local Security Authority (LSA) Denial of Service Vulnerability Windows Local Security Authority (LSA) Denial of Service Vulnerability FAQ: According to the CVSS metric, the attack vector is adjacent (AV:A). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires that an attacker will need to first gain access to the restricted network before running an attack. Windows Local Security Authority (LSA): Windows Local Securi
msrc
CVE-2023-35316MEDIUMCVSS 6.52023-07-11
CVE-2023-35316 [MEDIUM] CWE-125 Remote Procedure Call Runtime Information Disclosure Vulnerability Remote Procedure Call Runtime Information Disclosure Vulnerability FAQ: What type of information could be disclosed by this vulnerability? An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory. Windows Remote Procedure Call: Windows Remote Procedure Call Microsoft: Microsoft Customer Action Required: Yes Impact: Information Disclosure E
msrc
CVE-2023-33173MEDIUMCVSS 6.52023-07-11
CVE-2023-33173 [MEDIUM] CWE-126 Remote Procedure Call Runtime Denial of Service Vulnerability Remote Procedure Call Runtime Denial of Service Vulnerability Windows Remote Procedure Call: Windows Remote Procedure Call Microsoft: Microsoft Customer Action Required: Yes Impact: Denial of Service Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5028168 Reference:
msrc
CVE-2023-32015CRITICALCVSS 9.82023-06-13
CVE-2023-32015 [CRITICAL] CWE-20 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? When Windows message queuing service is running in a PGM Server environment, an attacker could send a specially crafted file over the network to achieve remote code execution and attempt to trigger malicious code. Windows PGM: Windows PGM Microsoft: Mic
msrc
CVE-2023-29363CRITICALCVSS 9.82023-06-13
CVE-2023-29363 [CRITICAL] CWE-122 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? When Windows message queuing service is running in a PGM Server environment, an attacker could send a specially crafted file over the network to achieve remote code execution and attempt to trigger malicious code. Windows PGM: Windows PGM Microsoft: Mi
msrc
CVE-2023-32014CRITICALCVSS 9.82023-06-13
CVE-2023-32014 [CRITICAL] CWE-191 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? When Windows message queuing service is running in a PGM Server environment, an attacker could send a specially crafted file over the network to achieve remote code execution and attempt to trigger malicious code. Windows PGM: Windows PGM Microsoft: Mi
msrc
CVE-2023-29351HIGHCVSS 8.12023-06-13
CVE-2023-29351 [HIGH] CWE-59 Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited this vulnerability could gain specific limited SYSTEM privileges. FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to no loss of confidentiality (C:N) but have major impact
msrc
CVE-2023-29364HIGHCVSS 7.02023-06-13
CVE-2023-29364 [HIGH] CWE-190 Windows Authentication Elevation of Privilege Vulnerability Windows Authentication Elevation of Privilege Vulnerability FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerabilit
msrc
CVE-2023-32011HIGHCVSS 7.52023-06-13
CVE-2023-32011 [HIGH] CWE-125 Windows iSCSI Discovery Service Denial of Service Vulnerability Windows iSCSI Discovery Service Denial of Service Vulnerability Windows iSCSI: Windows iSCSI Microsoft: Microsoft Customer Action Required: Yes Impact: Denial of Service Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5027222 Reference: https://support.microsoft.com/help/502
msrc
CVE-2023-32017HIGHCVSS 7.82023-06-13
CVE-2023-32017 [HIGH] CWE-125 Microsoft PostScript Printer Driver Remote Code Execution Vulnerability Microsoft PostScript Printer Driver Remote Code Execution Vulnerability FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution? The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out lo
msrc
CVE-2023-32021HIGHCVSS 7.12023-06-13
CVE-2023-32021 [HIGH] Windows SMB Witness Service Security Feature Bypass Vulnerability Windows SMB Witness Service Security Feature Bypass Vulnerability FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploited this vulnerability could execute RPC procedures that are restricted to privileged accounts, bypassing the access check for the RPC procedures. FAQ: How could an attacker exploit the vulnerability? To explo
msrc
CVE-2023-32022HIGHCVSS 7.62023-06-13
CVE-2023-32022 [HIGH] CWE-285 Windows Server Service Security Feature Bypass Vulnerability Windows Server Service Security Feature Bypass Vulnerability FAQ: How could an attacker exploit this vulnerability? To exploit this vulnerability, an attacker could execute a specially crafted malicious script which executes an RPC call to a Windows SMB Server Service. FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker who successfully exploite
msrc
CVE-2023-29373HIGHCVSS 8.82023-06-13
CVE-2023-29373 [HIGH] CWE-125 Microsoft ODBC Driver Remote Code Execution Vulnerability Microsoft ODBC Driver Remote Code Execution Vulnerability FAQ: How could an attacker exploit this vulnerability? An attacker could exploit the vulnerability by tricking an authenticated user into attempting to connect to a malicious SQL server via ODBC, which could result in the server receiving a malicious networking packet. This could allow the attacker to execute code remotely on the client. FAQ: Accordi
msrc
CVE-2023-29358HIGHCVSS 7.82023-06-13
CVE-2023-29358 [HIGH] CWE-416 Windows GDI Elevation of Privilege Vulnerability Windows GDI Elevation of Privilege Vulnerability FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. Windows GDI: Windows GDI Microsoft: Microsoft Customer Action Required: Yes Impact: Elevation of Privilege Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Relea
msrc
CVE-2023-29368HIGHCVSS 7.02023-06-13
CVE-2023-29368 [HIGH] CWE-415 Windows Filtering Platform Elevation of Privilege Vulnerability Windows Filtering Platform Elevation of Privilege Vulnerability FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited this vulnerability could gain administrator privileges. FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of thi
msrc