VendorsMicrosoftwindows_server_2012r2
Vulnerabilities

Microsoft Windows Server 2012 r2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4836CVEs
CVE-2015-1643
Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "NtCreateTransactionManager Type Confusion Vulnerability."
Published 2015-04-14 · Modified
7.2EPSS 0.027
CVE-2015-0058
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a crafted application, aka "Windows Cursor Object Double Free Vulnerability."
Published 2015-02-11 · Modified
7.21 PoCEPSS 0.027
CVE-2015-2549
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
Published 2015-10-14 · Modified
7.2EPSS 0.023
CVE-2024-26208
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2024-04-09 · Analyzed
7.2EPSS 0.023
CVE-2024-26195
DHCP Server Service Remote Code Execution Vulnerability
Published 2024-04-09 · Analyzed
7.2EPSS 0.022
CVE-2024-26202
DHCP Server Service Remote Code Execution Vulnerability
Published 2024-04-09 · Analyzed
7.2EPSS 0.022
CVE-2024-38044
DHCP Server Service Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
7.2EPSS 0.021
CVE-2024-38025
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
7.2EPSS 0.021
CVE-2024-38028
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
7.2EPSS 0.021
CVE-2024-49089
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
7.2EPSS 0.021
CVE-2014-1819
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly control access to objects associated with font files, which allows local users to gain privileges via a crafted file, aka "Font Double-Fetch Vulnerability."
Published 2014-08-12 · Modified
7.2EPSS 0.020
CVE-2014-1814
The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that invokes the repair feature for a different application, aka "Windows Installer Repair Vulnerability."
Published 2014-08-12 · Modified
7.2EPSS 0.020
CVE-2023-36401
Microsoft Remote Registry Service Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
7.2EPSS 0.019
CVE-2015-1720
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel Use After Free Vulnerability."
Published 2015-06-10 · Modified
7.2EPSS 0.019
CVE-2015-2478
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that triggers a Winsock call referencing an invalid address, aka "Winsock Elevation of Privilege Vulnerability."
Published 2015-11-11 · Modified
7.2EPSS 0.019
CVE-2015-2550
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."
Published 2015-10-14 · Modified
7.2EPSS 0.019
CVE-2015-2361
Hyper-V in Microsoft Windows 8.1 and Windows Server 2012 R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (buffer overflow) by leveraging guest OS privileges, aka "Hyper-V Buffer Overflow Vulnerability."
Published 2015-07-14 · Modified
7.2EPSS 0.019
CVE-2014-4074
The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via an application that schedules a crafted task, aka "Task Scheduler Vulnerability."
Published 2014-09-10 · Modified
7.2EPSS 0.019
CVE-2015-0073
The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain privileges via a crafted application, aka "Registry Virtualization Elevation of Privilege Vulnerability."
Published 2015-03-11 · Modified
7.2EPSS 0.018
CVE-2024-38019
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
7.2EPSS 0.018
CVE-2014-1807
The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly implement file associations, which allows local users to gain privileges via a crafted application, as exploited in the wild in May 2014, aka "Windows Shell File Association Vulnerability."
Published 2014-05-14 · Modified
7.2EPSS 0.018
CVE-2015-0062
Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to gain privileges via a crafted application that leverages incorrect impersonation handling in a process that uses the SeAssignPrimaryTokenPrivilege privilege, aka "Windows Create Process Elevation of Privilege Vulnerability."
Published 2015-02-11 · Modified
7.2EPSS 0.018
CVE-2024-38239
Windows Kerberos Elevation of Privilege Vulnerability
Published 2024-09-10 · Analyzed
7.2EPSS 0.017
CVE-2024-49091
Windows Domain Name Service Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
7.2EPSS 0.017
CVE-2015-0078
win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate the token of a calling thread, which allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Published 2015-03-11 · Modified
7.2EPSS 0.017
CVE-2015-2364
The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that leverages an incorrect bitmap conversion, aka "Graphics Component EOP Vulnerability."
Published 2015-07-14 · Modified
7.2EPSS 0.017
CVE-2015-2552
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of code, BitLocker, Device Encryption, and Device Health Attestation, via a crafted Boot Configuration Data (BCD) setting, aka "Trusted Boot Security Feature Bypass Vulnerability."
Published 2015-10-14 · Modified
7.2EPSS 0.017
CVE-2014-0300
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Published 2014-03-12 · Modified
7.2EPSS 0.016
CVE-2015-1644
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows MS-DOS Device Name Vulnerability."
Published 2015-04-14 · Modified
7.2EPSS 0.016
CVE-2015-2362
Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly initialize guest OS system data structures, which allows guest OS users to execute arbitrary code on the host OS by leveraging guest OS privileges, aka "Hyper-V System Data Structure Vulnerability."
Published 2015-07-14 · Modified
7.2EPSS 0.016
CVE-2015-6126
Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application, aka "Windows PGM UAF Elevation of Privilege Vulnerability."
Published 2015-12-09 · Modified
7.2EPSS 0.016
CVE-2023-28254
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
7.2EPSS 0.014
CVE-2024-29066
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Published 2024-04-09 · Analyzed
7.2EPSS 0.013
CVE-2023-23400
Windows DNS Server Remote Code Execution Vulnerability
Published 2023-03-14 · Modified
7.2EPSS 0.013
CVE-2023-35350
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
7.2EPSS 0.012
CVE-2018-8404
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8399.
Published 2018-08-15 · Modified
7.2EPSS 0.011
CVE-2020-1071
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog, aka 'Windows Remote Access Common Dialog Elevation of Privilege Vulnerability'.
Published 2020-05-21 · Modified
7.2EPSS 0.010
CVE-2020-1310
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1253.
Published 2020-06-09 · Modified
7.2EPSS 0.010
CVE-2020-1253
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1310.
Published 2020-06-09 · Modified
7.2EPSS 0.010
CVE-2023-32033
Microsoft Failover Cluster Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
7.2EPSS 0.009
← Prev80 / 121Next →