Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 105 of 152
CVE-2025-53796P3MEDIUMCVSS 6.5vr22025-09-09
CVE-2025-53796 [MEDIUM] CWE-126 CVE-2025-53796: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-58739P3MEDIUMCVSS 6.5vr22025-10-14
CVE-2025-58739 [MEDIUM] CWE-200 CVE-2025-58739: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2010-1689P3MEDIUMCVSS 6.4vr22010-05-07
CVE-2010-1689 [MEDIUM] CVE-2010-1689: The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs
nvd
CVE-2010-1690P3MEDIUMCVSS 6.4vr22010-05-07
CVE-2010-1690 [MEDIUM] CVE-2010-1690: The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction
nvd
CVE-2019-0758P3MEDIUMCVSS 6.5vr22019-05-16
CVE-2019-0758 [MEDIUM] CVE-2019-0758: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0882, CVE-2019-0961.
nvd
CVE-2022-26831P3HIGHCVSS 7.5vr22022-04-15
CVE-2022-26831 [HIGH] CVE-2022-26831: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2024-49096P3HIGHCVSS 7.5vr22024-12-12
CVE-2024-49096 [HIGH] CWE-400 CVE-2024-49096: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21230P3HIGHCVSS 7.5vr22025-01-14
CVE-2025-21230 [HIGH] CWE-20 CVE-2025-21230: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21251P3HIGHCVSS 7.5vr22025-01-14
CVE-2025-21251 [HIGH] CWE-400 CVE-2025-21251: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2024-38073P3HIGHCVSS 7.5vr22024-07-09
CVE-2024-38073 [HIGH] CWE-125 CVE-2024-38073: Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
nvd
CVE-2023-36703P3HIGHCVSS 7.5vr22023-10-10
CVE-2023-36703 [HIGH] CWE-400 CVE-2023-36703: DHCP Server Service Denial of Service Vulnerability
DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2025-21289P3HIGHCVSS 7.5vr22025-01-14
CVE-2025-21289 [HIGH] CWE-400 CVE-2025-21289: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21290P3HIGHCVSS 7.5vr22025-01-14
CVE-2025-21290 [HIGH] CWE-400 CVE-2025-21290: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2025-21270P3HIGHCVSS 7.5vr22025-01-14
CVE-2025-21270 [HIGH] CWE-400 CVE-2025-21270: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2015-0006P3MEDIUMCVSS 6.1vr22015-01-13
CVE-2015-0006 [MEDIUM] CWE-264 CVE-2015-0006: The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2
The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive c
nvd
CVE-2019-0936P3HIGHCVSS 7.8vr22019-05-16
CVE-2019-0936 [HIGH] CVE-2019-0936: An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly h
An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0734.
nvd
CVE-2024-38091P3HIGHCVSS 7.5vr22024-07-09
CVE-2024-38091 [HIGH] CWE-166 CVE-2024-38091: Microsoft WS-Discovery Denial of Service Vulnerability
Microsoft WS-Discovery Denial of Service Vulnerability
nvd
CVE-2019-1396P3HIGHCVSS 7.8vr22019-11-12
CVE-2019-1396 [HIGH] CVE-2019-1396: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1395, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1395P3HIGHCVSS 7.8vr22019-11-12
CVE-2019-1395 [HIGH] CVE-2019-1395: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1394, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd
CVE-2019-1394P3HIGHCVSS 7.8vr22019-11-12
CVE-2019-1394 [HIGH] CVE-2019-1394: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1393, CVE-2019-1395, CVE-2019-1396, CVE-2019-1408, CVE-2019-1434.
nvd