Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 150 of 152
CVE-2018-0810P4MEDIUMCVSS 4.7vr22018-02-15
CVE-2018-0810 [MEDIUM] CVE-2018-0810: The Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2, and Windows Server 2012 allows
The Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2, and Windows Server 2012 allows an information disclosure vulnerability due to the way memory is initialized, aka "Windows Kernel Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0757.
nvd
CVE-2015-2374P4LOWCVSS 3.3vr22015-07-14
CVE-2015-2374 [LOW] CWE-200 CVE-2015-2374: The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2
The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly implement domain-controller communication, which allows remote attackers to discover credentials by leveraging certain PDC access and spoofing the BDC role in a PDC communication channel, aka "Ele
nvd
CVE-2022-21900P4MEDIUMCVSS 4.6vr22022-01-11
CVE-2022-21900 [MEDIUM] CVE-2022-21900: Windows Hyper-V Security Feature Bypass Vulnerability
Windows Hyper-V Security Feature Bypass Vulnerability
nvd
CVE-2026-20828P4MEDIUMCVSS 4.6vr2-sp12026-01-13
CVE-2026-20828 [MEDIUM] CWE-125 CVE-2026-20828: Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to d
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.
nvd
CVE-2015-2476P4LOWCVSS 2.6vr22015-08-15
CVE-2015-2476 [LOW] CWE-310 CVE-2015-2476: The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 supports SSL 2.0, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and conducting a decryption attack, aka
nvd
CVE-2022-29121P4MEDIUMCVSS 6.5vr2vsp22022-05-10
CVE-2022-29121 [MEDIUM] CVE-2022-29121: Windows WLAN AutoConfig Service Denial of Service Vulnerability
Windows WLAN AutoConfig Service Denial of Service Vulnerability
nvd
CVE-2016-3354P4LOWCVSS 3.3vr22016-09-14
CVE-2016-3354 [LOW] CWE-254 CVE-2016-3354: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability."
nvd
CVE-2019-0754P4MEDIUMCVSS 5.5vr22019-04-09
CVE-2019-0754 [MEDIUM] CVE-2019-0754: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
nvd
CVE-2019-1391P4MEDIUMCVSS 5.5vr22019-11-12
CVE-2019-1391 [MEDIUM] CVE-2019-1391: A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Win
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2018-12207.
nvd
CVE-2019-0600P4MEDIUMCVSS 4.7vr22019-03-05
CVE-2019-0600 [MEDIUM] CVE-2019-0600: An information disclosure vulnerability exists when the Human Interface Devices (HID) component impr
An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HID Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0601.
nvd
CVE-2018-8121P4MEDIUMCVSS 4.7v32-bit Systems Service Pack 2v32-bit Systems Service Pack 2 (Server Core installation)+3 more2018-06-14
CVE-2018-8121 [MEDIUM] CWE-665 CVE-2018-8121: An information disclosure vulnerability exists when the Windows kernel improperly initializes object
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207.
nvd
CVE-2025-59198P4MEDIUMCVSS 5.0vr22025-10-14
CVE-2025-59198 [MEDIUM] CWE-20 CVE-2025-59198: Improper input validation in Microsoft Windows Search Component allows an authorized attacker to den
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
nvd
CVE-2021-28316P4MEDIUMCVSS 4.6vr22021-04-13
CVE-2021-28316 [MEDIUM] CVE-2021-28316: Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability
nvd
CVE-2023-36722P4MEDIUMCVSS 4.4vr22023-10-10
CVE-2023-36722 [MEDIUM] CWE-284 CVE-2023-36722: Active Directory Domain Services Information Disclosure Vulnerability
Active Directory Domain Services Information Disclosure Vulnerability
nvd
CVE-2012-0174P4LOWCVSS 1.7vr22012-05-09
CVE-2012-0174 [LOW] CWE-264 CVE-2012-0174: Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP
Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass
nvd
CVE-2020-1194P4MEDIUMCVSS 5.5vr22020-06-09
CVE-2020-1194 [MEDIUM] CVE-2020-1194: A denial of service vulnerability exists when Windows Registry improperly handles filesystem operati
A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Registry Denial of Service Vulnerability'.
nvd
CVE-2019-0839P4MEDIUMCVSS 4.4vr22019-04-09
CVE-2019-0839 [MEDIUM] CVE-2019-0839: An information disclosure vulnerability exists when the Terminal Services component improperly discl
An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0838.
nvd
CVE-2019-0775P4MEDIUMCVSS 4.7vr22019-04-09
CVE-2019-0775 [MEDIUM] CVE-2019-0775: An information disclosure vulnerability exists when the Windows kernel improperly handles objects in
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0702, CVE-2019-0755, CVE-2019-0767, CVE-2019-0782.
nvd
CVE-2023-28276P4MEDIUMCVSS 4.4vr22023-04-11
CVE-2023-28276 [MEDIUM] CVE-2023-28276: Windows Group Policy Security Feature Bypass Vulnerability
Windows Group Policy Security Feature Bypass Vulnerability
nvd
CVE-2026-20936P4MEDIUMCVSS 4.3vr2-sp12026-01-13
CVE-2026-20936 [MEDIUM] CWE-125 CVE-2026-20936: Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a phys
Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
nvd