VendorsMicrosoftwindows_server_2012r2
Vulnerabilities

Microsoft Windows Server 2012 r2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4806CVEs
CVE-2026-69458
Windows BitLocker Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-69643
Windows Spaceport.sys Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-69371
Windows Overlay Filter Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-69423
Windows USB Video Driver Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-26111
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2026-03-10 · Analyzed
8.0EPSS 0.008
CVE-2026-69505
Windows NTFS Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-69427
Microsoft VOLSNAP.SYS Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-69332
Windows NTFS Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-68838
Windows NTFS Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-68834
Windows NTFS Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2026-68876
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.008
CVE-2022-21905
Windows Hyper-V Security Feature Bypass Vulnerability
Published 2022-01-11 · Modified
8.0EPSS 0.007
CVE-2026-69847
Windows DHCP Server Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.006
CVE-2026-69412
Windows DHCP Server Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.006
CVE-2026-50683
Windows DHCP Client Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
8.0EPSS 0.006
CVE-2026-69876
Windows DHCP Server Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
8.0EPSS 0.006
CVE-2026-50365
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
8.0EPSS 0.005
CVE-2026-33826
Windows Active Directory Remote Code Execution Vulnerability
Published 2026-04-14 · Analyzed
8.0EPSS 0.005
CVE-2021-34537
Windows Bluetooth Driver Elevation of Privilege Vulnerability
Published 2021-08-12 · Modified
8.0EPSS 0.005
CVE-2026-27912
Windows Kerberos Elevation of Privilege Vulnerability
Published 2026-04-14 · Analyzed
8.0EPSS 0.004
CVE-2026-48576
Secure Boot Security Feature Bypass Vulnerability
Published 2026-06-09 · Modified
7.9EPSS 0.023
CVE-2026-48573
Secure Boot Security Feature Bypass Vulnerability
Published 2026-06-09 · Modified
7.9EPSS 0.023
CVE-2026-48575
Secure Boot Security Feature Bypass Vulnerability
Published 2026-06-09 · Analyzed
7.9EPSS 0.004
CVE-2026-45588
Secure Boot Security Feature Bypass Vulnerability
Published 2026-06-09 · Analyzed
7.9EPSS 0.004
CVE-2026-47656
Windows Boot Manager Security Feature Bypass Vulnerability
Published 2026-06-09 · Analyzed
7.9EPSS 0.004
CVE-2026-48570
Secure Boot Security Feature Bypass Vulnerability
Published 2026-06-09 · Analyzed
7.9EPSS 0.004
CVE-2026-48568
Secure Boot Security Feature Bypass Vulnerability
Published 2026-06-09 · Analyzed
7.9EPSS 0.004
CVE-2026-48578
Secure Boot Security Feature Bypass Vulnerability
Published 2026-06-09 · Modified
7.9EPSS 0.003
CVE-2020-1147
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Published 2020-07-14 · Analyzed
7.8KEV2 PoCEPSS 0.940
CVE-2014-4113
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."
Published 2014-10-15 · Analyzed
7.8KEV4 PoCEPSS 0.869
CVE-2016-0041
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."
Published 2016-02-10 · Modified
7.81 PoCEPSS 0.829
CVE-2016-7255
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Published 2016-11-10 · Analyzed
7.8KEV3 PoCEPSS 0.810
CVE-2015-0015
Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (system hang and RADIUS outage) via crafted username strings to (1) Internet Authentication Service (IAS) or (2) Network Policy Server (NPS), aka "Network Policy Server RADIUS Implementation Denial of Service Vulnerability."
Published 2015-01-13 · Modified
7.8EPSS 0.787
CVE-2019-1458
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
Published 2019-12-10 · Analyzed
7.8KEV1 PoCEPSS 0.743
CVE-2021-40449
Win32k Elevation of Privilege Vulnerability
Published 2021-10-13 · Analyzed
7.8KEVEPSS 0.741
CVE-2018-8453
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-10-10 · Analyzed
7.8KEV1 PoCEPSS 0.700
CVE-2020-0938
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.
Published 2020-04-15 · Analyzed
7.8KEVEPSS 0.690
CVE-2022-34713
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Published 2022-08-09 · Analyzed
7.8KEVEPSS 0.678
CVE-2024-43572
Microsoft Management Console Remote Code Execution Vulnerability
Published 2024-10-08 · Analyzed
7.8KEVEPSS 0.667
CVE-2016-0151
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
Published 2016-04-12 · Analyzed
7.8KEV1 PoCEPSS 0.629
← Prev31 / 121Next →