Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 144 of 152
CVE-2017-11852P4MEDIUMCVSS 4.7vr22017-11-15
CVE-2017-11852 [MEDIUM] CWE-200 CVE-2017-11852: Microsoft GDI Component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker t
Microsoft GDI Component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to log on to an affected system and run a specially crafted application to compromise the user's system, due improperly disclosing kernel memory addresses, aka "Windows GDI Information Disclosure Vulnerability".
nvd
CVE-2017-8554P4MEDIUMCVSS 4.7vr22017-06-29
CVE-2017-8554 [MEDIUM] CWE-200 CVE-2017-8554: The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows R
The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticated attacker to obtain memory contents via a specially crafted application.
nvd
CVE-2015-2472P4MEDIUMCVSS 4.3vr22015-08-15
CVE-2015-2472 [MEDIUM] CWE-20 CVE-2015-2472: Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows
Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify certificates, which allows man-in-the-middle attackers to spoof clients via a cra
nvd
CVE-2020-24588P4LOWCVSS 3.5vr22021-05-11
CVE-2020-24588 [LOW] CWE-327 CVE-2020-24588: The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary
nvd
CVE-2025-21328P4MEDIUMCVSS 4.3vr22025-01-14
CVE-2025-21328 [MEDIUM] CWE-41 CVE-2025-21328: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21329P4MEDIUMCVSS 4.3vr22025-01-14
CVE-2025-21329 [MEDIUM] CWE-41 CVE-2025-21329: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2025-21352P4MEDIUMCVSS 6.5vr22025-02-11
CVE-2025-21352 [MEDIUM] CWE-400 CVE-2025-21352: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2024-38048P4MEDIUMCVSS 6.5vr22024-07-09
CVE-2024-38048 [MEDIUM] CWE-125 CVE-2024-38048: Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
nvd
CVE-2018-0855P4MEDIUMCVSS 4.3vr22018-02-15
CVE-2018-0855 [MEDIUM] CVE-2018-0855: The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Ser
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0755, CVE-2018-0760, and CVE-2018-0761.
nvd
CVE-2015-2535P4MEDIUMCVSS 4.0vr22015-09-09
CVE-2015-2535 [MEDIUM] CWE-17 CVE-2015-2535: Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows
Active Directory in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service outage) by creating multiple machine accounts, aka "Active Directory Denial of Service Vulnerability."
nvd
CVE-2021-31184P4MEDIUMCVSS 5.5vr22021-05-11
CVE-2021-31184 [MEDIUM] CVE-2021-31184: Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
nvd
CVE-2020-0962P4MEDIUMCVSS 5.5vr22020-04-15
CVE-2020-0962 [MEDIUM] CVE-2020-0962: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0699.
nvd
CVE-2020-0821P4MEDIUMCVSS 5.5vr22020-04-15
CVE-2020-0821 [MEDIUM] CVE-2020-0821: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1007.
nvd
CVE-2020-0736P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0736 [MEDIUM] CVE-2020-0736: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'.
nvd
CVE-2020-0698P4MEDIUMCVSS 5.5vr22020-02-11
CVE-2020-0698 [MEDIUM] CVE-2020-0698: An information disclosure vulnerability exists when the Telephony Service improperly discloses the c
An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'.
nvd
CVE-2017-0184P4MEDIUMCVSS 5.4vr22017-04-12
CVE-2017-0184 [MEDIUM] CVE-2017-0184: A denial of service vulnerability exists when Microsoft Hyper-V running on a host server fails to pr
A denial of service vulnerability exists when Microsoft Hyper-V running on a host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0183, CVE-2017-0185, and CVE-2017-0186.
nvd
CVE-2020-0874P4MEDIUMCVSS 5.5vr22020-03-12
CVE-2020-0874 [MEDIUM] CVE-2020-0874: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0774, CVE-2020-0879, CVE-2020-0880, CVE-2020-0882.
nvd
CVE-2020-17029P4MEDIUMCVSS 5.5vr22020-11-11
CVE-2020-17029 [MEDIUM] CVE-2020-17029: Windows Canonical Display Driver Information Disclosure Vulnerability
Windows Canonical Display Driver Information Disclosure Vulnerability
nvd
CVE-2020-1351P4MEDIUMCVSS 5.5vr22020-07-14
CVE-2020-1351 [MEDIUM] CVE-2020-1351: An information disclosure vulnerability exists when the Windows Graphics component improperly handle
An information disclosure vulnerability exists when the Windows Graphics component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'.
nvd
CVE-2020-0982P4MEDIUMCVSS 5.5vr22020-04-15
CVE-2020-0982 [MEDIUM] CVE-2020-0982: An information disclosure vulnerability exists when the Microsoft Windows Graphics Component imprope
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0987, CVE-2020-1005.
nvd