VendorsMicrosoftwindows_server_2012r2
Vulnerabilities

Microsoft Windows Server 2012 r2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4836CVEs
CVE-2020-1092
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1062.
Published 2020-05-21 · Modified
7.6EPSS 0.031
CVE-2019-1193
Microsoft Browser Memory Corruption Vulnerability
Published 2019-08-14 · Modified
7.6EPSS 0.031
CVE-2022-30142
Windows File History Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
7.6EPSS 0.022
CVE-2023-32022
Windows Server Service Security Feature Bypass Vulnerability
Published 2023-06-13 · Modified
7.6EPSS 0.008
CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Published 2024-02-14 · Modified
7.5EPSS 1.000
CVE-2017-0147
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."
Published 2017-03-17 · Analyzed
7.5KEV4 PoCEPSS 0.997
CVE-2023-36884
Windows Search Remote Code Execution Vulnerability
Published 2023-07-11 · Analyzed
7.5KEVEPSS 0.989
CVE-2024-29059
.NET Framework Information Disclosure Vulnerability
Published 2024-03-22 · Analyzed
7.5KEVEPSS 0.986
CVE-2023-28302
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2023-04-11 · Modified
7.5EPSS 0.926
CVE-2023-21769
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2023-04-11 · Modified
7.5EPSS 0.887
CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability
Published 2024-07-09 · Analyzed
7.5KEVEPSS 0.842
CVE-2024-49113
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Published 2024-12-10 · Analyzed
7.5EPSS 0.836
CVE-2021-42278
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2021-11-10 · Analyzed
7.5KEVEPSS 0.733
CVE-2023-36606
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2023-10-10 · Modified
7.5EPSS 0.672
CVE-2021-36942
Windows LSA Spoofing Vulnerability
Published 2021-08-12 · Analyzed
7.5KEVEPSS 0.660
CVE-2024-26212
DHCP Server Service Denial of Service Vulnerability
Published 2024-04-09 · Analyzed
7.5EPSS 0.626
CVE-2021-24086
Windows TCP/IP Denial of Service Vulnerability
Published 2021-02-25 · Modified
7.5EPSS 0.590
CVE-2025-21285
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2025-01-14 · Analyzed
7.5EPSS 0.557
CVE-2022-35748
HTTP.sys Denial of Service Vulnerability
Published 2023-05-31 · Modified
7.5EPSS 0.472
CVE-2023-21818
Windows Secure Channel Denial of Service Vulnerability
Published 2023-02-14 · Modified
7.5EPSS 0.432
CVE-2024-38178
Scripting Engine Memory Corruption Vulnerability
Published 2024-08-13 · Analyzed
7.5KEVEPSS 0.414
CVE-2025-21277
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Published 2025-01-14 · Analyzed
7.5EPSS 0.386
CVE-2022-34689
Windows CryptoAPI Spoofing Vulnerability
Published 2022-10-11 · Modified
7.5EPSS 0.379
CVE-2024-38071
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Published 2024-07-09 · Modified
7.5EPSS 0.359
CVE-2022-22025
Windows Internet Information Services Cachuri Module Denial of Service Vulnerability
Published 2022-07-12 · Modified
7.5EPSS 0.327
CVE-2025-30397
Scripting Engine Memory Corruption Vulnerability
Published 2025-05-13 · Analyzed
7.5KEV1 PoCEPSS 0.268
CVE-2016-0037
The forms-based authentication implementation in Active Directory Federation Services (ADFS) 3.0 in Microsoft Windows Server 2012 R2 allows remote attackers to cause a denial of service (daemon outage) via crafted data, aka "Microsoft Active Directory Federation Services Denial of Service Vulnerability."
Published 2016-02-10 · Modified
7.5EPSS 0.257
CVE-2025-53722
Windows Remote Desktop Services Denial of Service Vulnerability
Published 2025-08-12 · Analyzed
7.5EPSS 0.223
CVE-2016-3237
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via vectors related to a fallback to NTLM authentication during a domain account password change, aka "Kerberos Security Feature Bypass Vulnerability."
Published 2016-08-09 · Modified
7.51 PoCEPSS 0.172
CVE-2025-47984
Windows GDI Information Disclosure Vulnerability
Published 2025-07-08 · Analyzed
7.5EPSS 0.169
CVE-2016-0044
Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSvc service outage) via crafted "change batch" data, aka "Windows DLL Loading Denial of Service Vulnerability."
Published 2016-02-10 · Modified
7.5EPSS 0.142
CVE-2020-16896
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Published 2020-10-16 · Modified
7.5EPSS 0.126
CVE-2014-0316
Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (memory consumption) and bypass the ASLR protection mechanism via a crafted client that sends messages with an invalid data view, aka "LRPC ASLR Bypass Vulnerability."
Published 2014-08-12 · Modified
7.5EPSS 0.115
CVE-2023-38162
DHCP Server Service Denial of Service Vulnerability
Published 2023-09-12 · Modified
7.5EPSS 0.107
CVE-2019-1453
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
Published 2019-12-10 · Modified
7.5EPSS 0.099
CVE-2019-0545
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.
Published 2019-01-08 · Modified
7.5EPSS 0.096
CVE-2020-1374
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
7.5EPSS 0.091
CVE-2018-8360
An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.0, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 4.7.2, Microsoft .NET Framework 2.0, Microsoft .NET Framework 4.6/4.6.1/4.6.2.
Published 2018-08-15 · Modified
7.5EPSS 0.090
CVE-2018-0764
Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765.
Published 2018-01-10 · Modified
7.5EPSS 0.089
CVE-2018-8493
An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka "Windows TCP/IP Information Disclosure Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.
Published 2018-10-10 · Modified
7.5EPSS 0.084
← Prev68 / 121Next →