windows_server_2012_r2 vulnerabilities
CVEs whose affected-version data names the windows_server_2012_r2 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
428 CVEsRSS
CVE-2026-50402High· 7.8PoCNTFS Elevation of Privilege Vulnerability
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-50480High· 7.8Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.
CVE-2026-50476High· 7.8Windows Network Connections Service Elevation of Privilege Vulnerability
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
CVE-2026-50475Medium· 5.5Windows Kernel Information Disclosure Vulnerability
Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.
CVE-2026-50474High· 8.8Remote Desktop Client Remote Code Execution Vulnerability
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-50470High· 7.5Windows Network Policy Server SNMP Information Disclosure Vulnerability
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50461High· 7.8Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVE-2026-50453Medium· 6.1Windows USB Audio Class Driver Information Disclosure Vulnerability
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-50447Critical· 9.8Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
CVE-2026-50444High· 8.8Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
CVE-2026-50431Medium· 5.5Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability
CVE-2026-50394Medium· 5.5Windows Media Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.
CVE-2026-50505High· 7.5Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
CVE-2026-50502High· 8.0Windows Event Logging Service Remote Code Execution Vulnerability
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
CVE-2026-50500High· 7.5Windows Netlogon Elevation of Privilege Vulnerability
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.
CVE-2026-50498High· 7.8Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-50494High· 7.8Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50491High· 7.0Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability
Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.
CVE-2026-50490High· 7.0Windows Installer Elevation of Privilege Vulnerability
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-50489High· 8.8Win32k Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-50485Medium· 4.5Windows Hyper-V Denial of Service Vulnerability
Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
CVE-2026-50482High· 7.3Windows NTFS Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
CVE-2026-50477High· 8.8Windows Kernel Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-50518Critical· 9.8Windows DHCP Server Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
CVE-2026-50504Medium· 6.5Windows Remote Desktop Client Information Disclosure Vulnerability
Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-50497Medium· 6.5Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
CVE-2026-50496High· 7.5Windows Network Policy Server SNMP Information Disclosure Vulnerability
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
CVE-2026-50647High· 7.5Active Directory Federation Server Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-54121High· 8.8PoCActive Directory Certificate Services Elevation of Privilege Vulnerability
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
CVE-2026-54115High· 7.8Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.