Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 133 of 152
CVE-2020-1071P4MEDIUMCVSS 6.8vr22020-05-21
CVE-2020-1071 [MEDIUM] CWE-755 CVE-2020-1071: An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote
An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog, aka 'Windows Remote Access Common Dialog Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1333P4MEDIUMCVSS 6.7vr22020-07-14
CVE-2020-1333 [MEDIUM] CVE-2020-1333: An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improper
An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.
nvd
CVE-2020-1253P4MEDIUMCVSS 6.7vr22020-06-09
CVE-2020-1253 [MEDIUM] CVE-2020-1253: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1251, CVE-2020-1310.
nvd
CVE-2021-43224P4MEDIUMCVSS 5.5vr22021-12-15
CVE-2021-43224 [MEDIUM] CVE-2021-43224: Windows Common Log File System Driver Information Disclosure Vulnerability
Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2020-1251P4MEDIUMCVSS 6.7vr22020-06-09
CVE-2020-1251 [MEDIUM] CVE-2020-1251: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1207, CVE-2020-1247, CVE-2020-1253, CVE-2020-1310.
nvd
CVE-2017-8677P4MEDIUMCVSS 5.5vr22017-09-13
CVE-2017-8677 [MEDIUM] CWE-200 CVE-2017-8677: The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
The Windows GDI+ component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly discloses kernel memory addresses, aka "Win32k Information Disclosure V
nvd
CVE-2017-8679P4MEDIUMCVSS 5.5vr22017-09-13
CVE-2017-8679 [MEDIUM] CWE-200 CVE-2017-8679: The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure
nvd
CVE-2025-21226P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21226 [MEDIUM] CWE-125 CVE-2025-21226: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21260P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21260 [MEDIUM] CWE-125 CVE-2025-21260: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21256P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21256 [MEDIUM] CWE-122 CVE-2025-21256: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21249P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21249 [MEDIUM] CWE-125 CVE-2025-21249: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21228P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21228 [MEDIUM] CWE-125 CVE-2025-21228: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21258P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21258 [MEDIUM] CWE-125 CVE-2025-21258: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21232P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21232 [MEDIUM] CWE-125 CVE-2025-21232: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21255P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21255 [MEDIUM] CWE-125 CVE-2025-21255: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21324P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21324 [MEDIUM] CWE-125 CVE-2025-21324: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21227P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21227 [MEDIUM] CWE-125 CVE-2025-21227: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2025-21310P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21310 [MEDIUM] CWE-125 CVE-2025-21310: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd
CVE-2015-6112P4MEDIUMCVSS 5.8vr22015-11-11
CVE-2015-6112 [MEDIUM] CWE-20 CVE-2015-6112: SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows
SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allow
nvd
CVE-2025-21263P4MEDIUMCVSS 6.6vr22025-01-14
CVE-2025-21263 [MEDIUM] CWE-125 CVE-2025-21263: Windows Digital Media Elevation of Privilege Vulnerability
Windows Digital Media Elevation of Privilege Vulnerability
nvd