Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 103 of 152
CVE-2020-1360P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1360 [HIGH] CVE-2020-1360: An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles f
An elevation of privilege vulnerability exists when the Windows Profile Service improperly handles file operations, aka 'Windows Profile Service Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1196P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1196 [HIGH] CVE-2020-1196: An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects i
An elevation of privilege vulnerability exists in the way that the printconfig.dll handles objects in memory, aka 'Windows Print Configuration Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1302P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1302 [HIGH] CVE-2020-1302: An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Insta
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1272, CVE-2020-1277,
nvd
CVE-2022-21884P3HIGHCVSS 7.8vr22022-01-11
CVE-2022-21884 [HIGH] CVE-2022-21884: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2017-0298P3HIGHCVSS 7.3vr22017-06-15
CVE-2017-0298 [HIGH] CVE-2017-0298: A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive user, allows an authenticated attacker to run arbitrary code in another user's session, aka "Windows COM
nvd
CVE-2023-36004P3HIGHCVSS 7.5vr22023-12-12
CVE-2023-36004 [HIGH] CWE-287 CVE-2023-36004: Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
nvd
CVE-2017-0073P4MEDIUMCVSS 4.3vr22017-03-17
CVE-2017-0073 [MEDIUM] CVE-2017-0073: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows GDI+ Information Disclosure Vul
nvd
CVE-2021-24103P3HIGHCVSS 7.8vr22021-02-25
CVE-2021-24103 [HIGH] CVE-2021-24103: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2021-43245P3HIGHCVSS 7.8vr22021-12-15
CVE-2021-43245 [HIGH] CVE-2021-43245: Windows Digital TV Tuner Elevation of Privilege Vulnerability
Windows Digital TV Tuner Elevation of Privilege Vulnerability
nvd
CVE-2021-43248P3HIGHCVSS 7.8vr22021-12-15
CVE-2021-43248 [HIGH] CVE-2021-43248: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2021-24102P3HIGHCVSS 7.8vr22021-02-25
CVE-2021-24102 [HIGH] CWE-269 CVE-2021-24102: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2022-41095P3HIGHCVSS 7.8vr22022-11-09
CVE-2022-41095 [HIGH] CVE-2022-41095: Windows Digital Media Receiver Elevation of Privilege Vulnerability
Windows Digital Media Receiver Elevation of Privilege Vulnerability
nvd
CVE-2021-38671P3HIGHCVSS 7.8vr22021-09-15
CVE-2021-38671 [HIGH] CWE-269 CVE-2021-38671: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-38667P3HIGHCVSS 7.8vr22021-09-15
CVE-2021-38667 [HIGH] CWE-269 CVE-2021-38667: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-36927P3HIGHCVSS 7.8vr22021-08-12
CVE-2021-36927 [HIGH] CWE-269 CVE-2021-36927: Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability
Windows Digital TV Tuner device registration application Elevation of Privilege Vulnerability
nvd
CVE-2021-38630P3HIGHCVSS 7.8vr22021-09-15
CVE-2021-38630 [HIGH] CWE-269 CVE-2021-38630: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2021-36964P3HIGHCVSS 7.8vr22021-09-15
CVE-2021-36964 [HIGH] CWE-269 CVE-2021-36964: Windows Event Tracing Elevation of Privilege Vulnerability
Windows Event Tracing Elevation of Privilege Vulnerability
nvd
CVE-2017-0055P3MEDIUMCVSS 6.1vr22017-03-17
CVE-2017-0055 [MEDIUM] CWE-79 CVE-2017-0055: Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Wi
Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, a
nvd
CVE-2025-21331P3HIGHCVSS 7.3vr22025-01-14
CVE-2025-21331 [HIGH] CWE-59 CVE-2025-21331: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2023-21820P3HIGHCVSS 7.4vr22023-02-14
CVE-2023-21820 [HIGH] CWE-126 CVE-2023-21820: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd