cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 124 of 152
CVE-2011-1228P4HIGHCVSS 7.2vr22011-04-13
CVE-2011-1228 [HIGH] CVE-2011-1228: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type
nvd
CVE-2011-1232P4HIGHCVSS 7.2vr22011-04-13
CVE-2011-1232 [HIGH] CVE-2011-1232: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type
nvd
CVE-2011-1227P4HIGHCVSS 7.2vr22011-04-13
CVE-2011-1227 [HIGH] CVE-2011-1227: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type
nvd
CVE-2011-1233P4HIGHCVSS 7.2vr22011-04-13
CVE-2011-1233 [HIGH] CVE-2011-1233: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type
nvd
CVE-2011-0677P4HIGHCVSS 7.2vr22011-04-13
CVE-2011-0677 [HIGH] CVE-2011-0677: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type
nvd
CVE-2011-1880P4HIGHCVSS 7.2vr22011-07-13
CVE-2011-1880 [HIGH] CVE-2011-1880: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-
nvd
CVE-2011-1885P4HIGHCVSS 7.2vr22011-07-13
CVE-2011-1885 [HIGH] CVE-2011-1885: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-
nvd
CVE-2024-30019P4MEDIUMCVSS 6.5vr22024-05-14
CVE-2024-30019 [MEDIUM] CWE-400 CVE-2024-30019: DHCP Server Service Denial of Service Vulnerability DHCP Server Service Denial of Service Vulnerability
nvd
CVE-2018-0817P4HIGHCVSS 7.0vr22018-03-14
CVE-2018-0817 [HIGH] CVE-2018-0817: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows
nvd
CVE-2022-22042P4MEDIUMCVSS 6.5vr22022-07-12
CVE-2022-22042 [MEDIUM] CVE-2022-22042: Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2018-0816P4HIGHCVSS 7.0vr22018-03-14
CVE-2018-0816 [HIGH] CVE-2018-0816: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows
nvd
CVE-2017-11853P4MEDIUMCVSS 5.5vr22017-11-15
CVE-2017-11853 [MEDIUM] CVE-2017-11853: Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows an attacker to log in and run a specially crafted application due to the Windows kernel improperly initializing a memory address, aka "Window
nvd
CVE-2018-0868P4HIGHCVSS 7.0vr22018-03-14
CVE-2018-0868 [HIGH] CWE-20 CVE-2018-0868: Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how input is sanitized, aka "Windows Installer Elevation of Privilege
nvd
CVE-2022-24498P4MEDIUMCVSS 6.5vr22022-04-15
CVE-2022-24498 [MEDIUM] CVE-2022-24498: Windows iSCSI Target Service Information Disclosure Vulnerability Windows iSCSI Target Service Information Disclosure Vulnerability
nvd
CVE-2019-0984P4HIGHCVSS 7.0vr22019-06-12
CVE-2019-0984 [HIGH] CVE-2019-0984: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted appli
nvd
CVE-2024-21356P4MEDIUMCVSS 6.5vr22024-02-13
CVE-2024-21356 [MEDIUM] CWE-476 CVE-2024-21356: Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
nvd
CVE-2019-1338P4MEDIUMCVSS 5.9vr22019-10-10
CVE-2019-1338 [MEDIUM] CVE-2019-1338: A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacke A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLMv2 protection if a client is also sending LMv2 responses, aka 'Windows NTLM Security Feature Bypass Vulnerability'.
nvd
CVE-2022-22717P4HIGHCVSS 7.0vr22022-02-09
CVE-2022-22717 [HIGH] CVE-2022-22717: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2022-22036P4HIGHCVSS 7.0vr22022-07-12
CVE-2022-22036 [HIGH] CVE-2022-22036: Performance Counters for Windows Elevation of Privilege Vulnerability Performance Counters for Windows Elevation of Privilege Vulnerability
nvd
CVE-2022-30224P4HIGHCVSS 7.0vr22022-07-12
CVE-2022-30224 [HIGH] CVE-2022-30224: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase