Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 117 of 152
CVE-2023-21811P3HIGHCVSS 7.5vr22023-02-14
CVE-2023-21811 [HIGH] CWE-126 CVE-2023-21811: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-21700P3HIGHCVSS 7.5vr22023-02-14
CVE-2023-21700 [HIGH] CWE-476 CVE-2023-21700: Windows iSCSI Discovery Service Denial of Service Vulnerability
Windows iSCSI Discovery Service Denial of Service Vulnerability
nvd
CVE-2023-21702P3HIGHCVSS 7.5vr22023-02-14
CVE-2023-21702 [HIGH] CWE-125 CVE-2023-21702: Windows iSCSI Service Denial of Service Vulnerability
Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2023-20588P4MEDIUMCVSS 5.5vr22023-08-08
CVE-2023-20588 [MEDIUM] CWE-369 CVE-2023-20588: A division-by-zero error on some AMD processors can potentially return speculative data resulting i
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
nvd
CVE-2011-1281P4HIGHCVSS 7.2vr22011-07-13
CVE-2011-1281 [HIGH] CWE-119 CVE-2011-1281: The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2
The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or ca
nvd
CVE-2015-1720P4HIGHCVSS 7.2vr22015-06-10
CVE-2015-1720 [HIGH] CWE-416 CVE-2015-1720: Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Microsoft Windows Kernel U
nvd
CVE-2012-1848P4HIGHCVSS 7.2vr22012-05-09
CVE-2012-1848 [HIGH] CWE-20 CVE-2012-1848: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Sc
nvd
CVE-2012-1893P4HIGHCVSS 7.2vr22012-07-10
CVE-2012-1893 [HIGH] CWE-20 CVE-2012-1893: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Inc
nvd
CVE-2011-2011P4HIGHCVSS 7.2vr22011-10-12
CVE-2011-2011 [HIGH] CWE-399 CVE-2011-2011: Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 an
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After
nvd
CVE-2011-3408P4HIGHCVSS 7.2vr22011-12-14
CVE-2011-3408 [HIGH] CWE-264 CVE-2011-3408: Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft W
Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high
nvd
CVE-2015-2552P4HIGHCVSS 7.2vr22015-10-14
CVE-2015-2552 [HIGH] CWE-254 CVE-2015-2552: The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of code, BitLocker, Device Encryption, and Device Health Attestation, via a crafted Boot Configuratio
nvd
CVE-2012-0178P4HIGHCVSS 7.2vr22012-05-09
CVE-2012-0178 [HIGH] CWE-264 CVE-2012-0178: Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows S
Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Ma
nvd
CVE-2011-0662P4HIGHCVSS 7.2vr22011-04-13
CVE-2011-0662 [HIGH] CWE-399 CVE-2011-0662: Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 an
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a diffe
nvd
CVE-2015-2368P4MEDIUMCVSS 6.9vr22015-07-14
CVE-2015-2368 [MEDIUM] CVE-2015-2368: Untrusted search path vulnerability in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows
Untrusted search path vulnerability in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Windows DLL Remote Code Execution Vulnerability."
nvd
CVE-2022-38042P3HIGHCVSS 7.1vr22022-10-11
CVE-2022-38042 [HIGH] CVE-2022-38042: Active Directory Domain Services Elevation of Privilege Vulnerability
Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2022-26936P3MEDIUMCVSS 6.5vr2vsp22022-05-10
CVE-2022-26936 [MEDIUM] CVE-2022-26936: Windows Server Service Information Disclosure Vulnerability
Windows Server Service Information Disclosure Vulnerability
nvd
CVE-2019-1043P4MEDIUMCVSS 6.4vr22019-06-12
CVE-2019-1043 [MEDIUM] CVE-2019-1043: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory.
A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current
nvd
CVE-2022-22015P3MEDIUMCVSS 6.5vr22022-05-10
CVE-2022-22015 [MEDIUM] CVE-2022-22015: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2024-49082P4MEDIUMCVSS 6.8vr22024-12-12
CVE-2024-49082 [MEDIUM] CWE-22 CVE-2024-49082: Windows File Explorer Information Disclosure Vulnerability
Windows File Explorer Information Disclosure Vulnerability
nvd
CVE-2019-1014P4HIGHCVSS 7.0vr22019-06-12
CVE-2019-1014 [HIGH] CVE-2019-1014: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vul
nvd