Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 113 of 152
CVE-2023-28256P3MEDIUMCVSS 6.6vr22023-04-11
CVE-2023-28256 [MEDIUM] CWE-591 CVE-2023-28256: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2025-54097P3MEDIUMCVSS 6.5vr22025-09-09
CVE-2025-54097 [MEDIUM] CWE-125 CVE-2025-54097: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54096P3MEDIUMCVSS 6.5vr22025-09-09
CVE-2025-54096 [MEDIUM] CWE-125 CVE-2025-54096: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54095P3MEDIUMCVSS 6.5vr22025-09-09
CVE-2025-54095 [MEDIUM] CWE-125 CVE-2025-54095: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2017-8582P4MEDIUMCVSS 5.9vr22017-07-11
CVE-2017-8582 [MEDIUM] CWE-200 CVE-2017-8582: HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when the component improperly handles objects in memory, aka "Https.sys Information Disclosure Vulnerability
nvd
CVE-2013-3876P4HIGHCVSS 7.1vr22013-11-18
CVE-2013-3876 [HIGH] CWE-20 CVE-2013-3876: DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2
DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read
nvd
CVE-2015-0005P4MEDIUMCVSS 4.3vr22015-03-11
CVE-2015-0005 [MEDIUM] CWE-254 CVE-2015-0005: The NETLOGON service in Microsoft Windows Server 2003 SP2, Windows Server 2008 SP2 and R2 SP1, and W
The NETLOGON service in Microsoft Windows Server 2003 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2, when a Domain Controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive session information, by running a crafted application and leveraging the abil
nvd
CVE-2019-0821P3MEDIUMCVSS 6.5vr22019-04-09
CVE-2019-0821 [MEDIUM] CVE-2019-0821: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0703, CVE-2019-0704.
nvd
CVE-2010-1255P4MEDIUMCVSS 6.8vr22010-06-08
CVE-2010-1255 [MEDIUM] CWE-94 CVE-2010-1255: The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."
nvd
CVE-2021-31968P3HIGHCVSS 7.5vr2vsp22021-06-08
CVE-2021-31968 [HIGH] CVE-2021-31968: Windows Remote Desktop Services Denial of Service Vulnerability
Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2017-0274P3MEDIUMCVSS 5.9vr22017-05-12
CVE-2017-0274 [MEDIUM] CVE-2017-0274: Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way
Microsoft Server Message Block 1.0 (SMBv1) allows an information disclosure vulnerability in the way that Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 handles certain requests, aka "Windows SMB Information Disclosure Vul
nvd
CVE-2022-35833P3HIGHCVSS 7.5vr22022-09-13
CVE-2022-35833 [HIGH] CVE-2022-35833: Windows Secure Channel Denial of Service Vulnerability
Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2015-2369P4MEDIUMCVSS 6.9vr22015-07-14
CVE-2015-2369 [MEDIUM] CVE-2015-2369: Untrusted search path vulnerability in Windows Media Device Manager in Microsoft Windows Server 2003
Untrusted search path vulnerability in Windows Media Device Manager in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rtf file, aka "DLL Planting Remote Code
nvd
CVE-2023-36585P3HIGHCVSS 7.5vr22023-10-10
CVE-2023-36585 [HIGH] CWE-20 CVE-2023-36585: Windows upnphost.dll Denial of Service Vulnerability
Windows upnphost.dll Denial of Service Vulnerability
nvd
CVE-2023-36395P3HIGHCVSS 7.5vr2vsp22023-11-14
CVE-2023-36395 [HIGH] CWE-190 CVE-2023-36395: Windows Deployment Services Denial of Service Vulnerability
Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2022-34701P3HIGHCVSS 7.5vr22022-08-09
CVE-2022-34701 [HIGH] CWE-400 CVE-2022-34701: Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability
nvd
CVE-2016-3226P4MEDIUMCVSS 6.5vr22016-06-16
CVE-2016-3226 [MEDIUM] CWE-284 CVE-2016-3226: Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote a
Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory Denial of Service Vulnerability."
nvd
CVE-2016-3299P4MEDIUMCVSS 5.3vr22016-08-09
CVE-2016-3299 [MEDIUM] CWE-284 CVE-2016-3299: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to hijack network traffic or bypass intended Enhanced Protected Mode (EPM) or application container protection mechanisms, and consequently render untrusted co
nvd
CVE-2020-1097P3MEDIUMCVSS 6.5vr22020-09-11
CVE-2020-1097 [MEDIUM] CVE-2020-1097: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2022-33645P3HIGHCVSS 7.5vr22022-10-11
CVE-2022-33645 [HIGH] CVE-2022-33645: Windows TCP/IP Driver Denial of Service Vulnerability
Windows TCP/IP Driver Denial of Service Vulnerability
nvd