Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
331
Exploited in wild
132
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 146 of 152
CVE-2012-0157HIGHCVSS 8.4vr22012-03-13
CVE-2012-0157 [HIGH] CWE-20 CVE-2012-0157: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Fun
nvd
CVE-2012-0006MEDIUMCVSS 5.0vr22012-03-13
CVE-2012-0006 [MEDIUM] CWE-399 CVE-2012-0006: The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not pro The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
nvd
CVE-2012-0152MEDIUMCVSS 4.3vr22012-03-13
CVE-2012-0152 [MEDIUM] CWE-20 CVE-2012-0152: The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
nvd
CVE-2012-0156MEDIUMCVSS 4.3vr22012-03-13
CVE-2012-0156 [MEDIUM] CWE-20 CVE-2012-0156: DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 G DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
nvd
CVE-2012-1194MEDIUMCVSS 6.4≤ -2012-02-17
CVE-2012-1194 [MEDIUM] CVE-2012-1194: The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
nvd
CVE-2012-0150CRITICALCVSS 9.3vr22012-02-14
CVE-2012-0150 [CRITICAL] CWE-119 CVE-2012-0150: Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."
nvd
CVE-2012-0148HIGHCVSS 7.2vr22012-02-14
CVE-2012-0148 [HIGH] CWE-20 CVE-2012-0148: afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windo afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elev
nvd
CVE-2012-0154HIGHCVSS 7.2vr22012-02-14
CVE-2012-0154 [HIGH] CWE-399 CVE-2012-0154: Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 an Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Fre
nvd
CVE-2012-0004CRITICALCVSS 9.3vr22012-01-10
CVE-2012-0004 [CRITICAL] CVE-2012-0004: Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Serv Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filte
nvd
CVE-2012-0013CRITICALCVSS 9.3PoCvr22012-01-10
CVE-2012-0013 [CRITICAL] CVE-2012-0013: Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .applica
nvd
CVE-2012-0001CRITICALCVSS 9.3vr22012-01-10
CVE-2012-0001 [CRITICAL] CVE-2012-0001: The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2 The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Ker
nvd
CVE-2012-0003HIGHCVSS 8.1PoCvr22012-01-10
CVE-2012-0003 [HIGH] CVE-2012-0003: Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) i Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."
nvd
CVE-2011-3417CRITICALCVSS 9.3vr22011-12-30
CVE-2011-3417 [CRITICAL] CWE-264 CVE-2011-3417: The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 S The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnera
nvd
CVE-2011-5046CRITICALCVSS 9.3PoCvr22011-12-30
CVE-2011-5046 [CRITICAL] CWE-20 CVE-2011-5046: The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of servi
nvd
CVE-2011-3416HIGHCVSS 8.5vr22011-12-30
CVE-2011-3416 [HIGH] CWE-264 CVE-2011-3416: The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 S The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
nvd
CVE-2011-3414HIGHCVSS 7.8vr22011-12-30
CVE-2011-3414 [HIGH] CWE-399 CVE-2011-3414: The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU
nvd
CVE-2011-3415MEDIUMCVSS 6.8vr22011-12-30
CVE-2011-3415 [MEDIUM] CWE-20 CVE-2011-3415: Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsof Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."
nvd
CVE-2011-3406HIGHCVSS 8.8vr22011-12-14
CVE-2011-3406 [HIGH] CWE-119 CVE-2011-3406: Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a cr
nvd
CVE-2011-3408HIGHCVSS 7.2vr22011-12-14
CVE-2011-3408 [HIGH] CWE-264 CVE-2011-3408: Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft W Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high
nvd
CVE-2011-4434LOWCVSS 3.6vr22011-11-11
CVE-2011-4434 [LOW] CWE-264 CVE-2011-4434: Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLo Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
nvd