Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 26 of 152
CVE-2025-27740P2HIGHCVSS 8.8vr22025-04-08
CVE-2025-27740 [HIGH] CWE-1390 CVE-2025-27740: Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker t
Weak authentication in Windows Active Directory Certificate Services allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2010-0811P3CRITICALCVSS 9.3vr22010-06-08
CVE-2010-0811 [CRITICAL] CWE-94 CVE-2010-0811: Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX co
Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vect
nvd
CVE-2019-1333P2HIGHCVSS 8.8vr22019-10-10
CVE-2019-1333 [HIGH] CVE-2019-1333: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.
nvd
CVE-2025-26670P2HIGHCVSS 8.1vr22025-04-08
CVE-2025-26670 [HIGH] CWE-416 CVE-2025-26670: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2016-0098P2HIGHCVSS 8.8vr22016-03-09
CVE-2016-0098 [HIGH] CWE-20 CVE-2016-0098: Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W
Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 allow remote attackers to execute arbitrary code via crafted media content, aka "Windows Media Parsing Remote Code Execution Vulnerability."
nvd
CVE-2022-44666P3HIGHCVSS 7.8vr22022-12-13
CVE-2022-44666 [HIGH] CVE-2022-44666: Windows Contacts Remote Code Execution Vulnerability
Windows Contacts Remote Code Execution Vulnerability
nvd
CVE-2017-8528P3HIGHCVSS 8.8vr22017-06-15
CVE-2017-8528 [HIGH] CVE-2017-8528: Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gol
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, and Microsoft Office 2010 SP2 allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Uniscribe Remote Code Execu
nvd
CVE-2012-0150P3CRITICALCVSS 9.3vr22012-02-14
CVE-2012-0150 [CRITICAL] CWE-119 CVE-2012-0150: Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP
Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."
nvd
CVE-2016-3228P2HIGHCVSS 8.8vr22016-06-16
CVE-2016-3228 [HIGH] CWE-20 CVE-2016-3228: Microsoft Windows Server 2008 SP2 and R2 SP1 and Windows Server 2012 Gold and R2 allow remote authen
Microsoft Windows Server 2008 SP2 and R2 SP1 and Windows Server 2012 Gold and R2 allow remote authenticated users to execute arbitrary code via a crafted NetLogon request, aka "Windows Netlogon Memory Corruption Remote Code Execution Vulnerability."
nvd
CVE-2019-0902P3HIGHCVSS 8.8vr22019-05-16
CVE-2019-0902 [HIGH] CVE-2019-0902: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0889, CVE-2019-0890, CVE-2019-0891, CVE-2019-0893, CVE-2019-0894, CVE-2019-0895, CVE-2019-0896, CVE-2019-0897, CVE-2019-0898, CVE-2019-0899, CVE
nvd
CVE-2018-8332P3HIGHCVSS 8.8v32-bit Systems Service Pack 2v32-bit Systems Service Pack 2 (Server Core installation)+3 more2018-09-13
CVE-2018-8332 [HIGH] CVE-2018-8332: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, Windows Server 2016, Windows
nvd
CVE-2017-8527P3HIGHCVSS 8.8vr22017-06-15
CVE-2017-8527 [HIGH] CWE-119 CVE-2017-8527: Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Graphics Remote Code Execution Vulnerability".
nvd
CVE-2020-0687P2HIGHCVSS 8.8vr22020-04-15
CVE-2020-0687 [HIGH] CVE-2020-0687: A remote code execution vulnerability exists when the Windows font library improperly handles specia
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2016-0184P3HIGHCVSS 8.8vr22016-05-11
CVE-2016-0184 [HIGH] CVE-2016-0184: Use-after-free vulnerability in GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 S
Use-after-free vulnerability in GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted document, aka "Direct3D Use After Free Vulnerability."
nvd
CVE-2017-0062P3MEDIUMCVSS 4.7PoCvr22017-03-17
CVE-2017-0062 [MEDIUM] CVE-2017-0062: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI+ Information Disclosure Vulnerabili
nvd
CVE-2015-1725P3HIGHCVSS 7.2PoCvr22015-06-10
CVE-2015-1725 [HIGH] CWE-119 CVE-2015-1725: Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Buffer Overflow Vulnerability."
nvd
CVE-2022-34722P2CRITICALCVSS 9.8vr22022-09-13
CVE-2022-34722 [CRITICAL] CVE-2022-34722: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2020-0964P2HIGHCVSS 8.8vr22020-04-15
CVE-2020-0964 [HIGH] CVE-2020-0964: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2022-35744P2CRITICALCVSS 9.8vr22023-05-31
CVE-2022-35744 [CRITICAL] CVE-2022-35744: Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
nvd
CVE-2023-36606P3HIGHCVSS 7.5vr22023-10-10
CVE-2023-36606 [HIGH] CWE-400 CVE-2023-36606: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd