cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 128 of 152
CVE-2015-0098P4HIGHCVSS 7.2vr22015-04-14
CVE-2015-0098 [HIGH] CWE-264 CVE-2015-0098: Task Scheduler in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain Task Scheduler in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges by triggering application execution by an invalid task, aka "Task Scheduler Elevation of Privilege Vulnerability."
nvd
CVE-2009-1126P4HIGHCVSS 7.2vsp22009-06-10
CVE-2009-1126 [HIGH] CWE-20 CVE-2009-1126: The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly vali The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."
nvd
CVE-2021-34507P4MEDIUMCVSS 6.5vr22021-07-14
CVE-2021-34507 [MEDIUM] CVE-2021-34507: Windows Remote Assistance Information Disclosure Vulnerability Windows Remote Assistance Information Disclosure Vulnerability
nvd
CVE-2021-34444P4MEDIUMCVSS 6.5vr22021-07-16
CVE-2021-34444 [MEDIUM] CVE-2021-34444: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2022-26934P4MEDIUMCVSS 6.5vr2vsp22022-05-10
CVE-2022-26934 [MEDIUM] CVE-2022-26934: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2019-0713P4MEDIUMCVSS 6.8vr22019-06-12
CVE-2019-0713 [MEDIUM] CWE-20 CVE-2019-0713: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that cau
nvd
CVE-2017-0244P4MEDIUMCVSS 6.7vr22017-05-12
CVE-2017-0244 [MEDIUM] CVE-2017-0244: The kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows locally authenticated att The kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows locally authenticated attackers to gain privileges via a crafted application, or in Windows 7 for x64-based systems, cause denial of service, aka "Windows Kernel Elevation of Privilege Vulnerability."
nvd
CVE-2020-17014P4HIGHCVSS 7.1vr22020-11-11
CVE-2020-17014 [HIGH] CVE-2020-17014: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2018-8404P4HIGHCVSS 7.0vr2-sp12018-08-15
CVE-2018-8404 [HIGH] CVE-2018-8404: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique fro
nvd
CVE-2022-30208P4MEDIUMCVSS 6.5vr22022-07-12
CVE-2022-30208 [MEDIUM] CVE-2022-30208: Windows Security Account Manager (SAM) Denial of Service Vulnerability Windows Security Account Manager (SAM) Denial of Service Vulnerability
nvd
CVE-2018-0788P4HIGHCVSS 7.0vr22018-01-04
CVE-2018-0788 [HIGH] CVE-2018-0788: The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Win The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 and R2 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability".
nvd
CVE-2018-8224P4HIGHCVSS 7.0vr2-sp1v32-bit Systems Service Pack 2+4 more2018-06-14
CVE-2018-8224 [HIGH] CWE-404 CVE-2018-8224: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
nvd
CVE-2018-8169P4HIGHCVSS 7.0vr2-sp1v32-bit Systems Service Pack 2+4 more2018-06-14
CVE-2018-8169 [HIGH] CWE-404 CVE-2018-8169: An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory, aka "HIDParser Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2018-8339P4HIGHCVSS 7.0vr2-sp1v32-bit Systems Service Pack 2+4 more2018-08-15
CVE-2018-8339 [HIGH] CWE-20 CVE-2018-8339: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows
nvd
CVE-2018-1036P4HIGHCVSS 7.0vr2v32-bit Systems Service Pack 2+4 more2018-06-14
CVE-2018-1036 [HIGH] CWE-732 CVE-2018-1036: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2022-21997P4HIGHCVSS 7.1vr22022-02-09
CVE-2022-21997 [HIGH] CWE-59 CVE-2022-21997: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2016-0008P4MEDIUMCVSS 4.3vr22016-01-13
CVE-2016-0008 [MEDIUM] CWE-200 CVE-2016-0008: The graphics device interface in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wi The graphics device interface in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Windows GDI32.dll ASLR Bypass Vulnerability."
nvd
CVE-2017-8593P4HIGHCVSS 7.0vr22017-08-08
CVE-2017-8593 [HIGH] CWE-281 CVE-2017-8593: Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2 Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
nvd
CVE-2022-22022P4HIGHCVSS 7.1vr22022-07-12
CVE-2022-22022 [HIGH] CVE-2022-22022: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2017-8577P4HIGHCVSS 7.0vr22017-07-11
CVE-2017-8577 [HIGH] CVE-2017-8577: Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability". This CVE ID is un
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase