cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 27 of 152
CVE-2020-0734P2HIGHCVSS 8.8vr22020-02-11
CVE-2020-0734 [HIGH] CVE-2020-0734: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0681.
nvd
CVE-2017-0103P3HIGHCVSS 7.0PoCvr22017-03-17
CVE-2017-0103 [HIGH] CWE-119 CVE-2017-0103: The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, an The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 mishandles registry objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Registry Elevation of Privilege Vulnerability."
nvd
CVE-2014-4118P2CRITICALCVSS 9.3vr22014-11-11
CVE-2014-4118 [CRITICAL] CWE-94 CVE-2014-4118: XML Core Services (aka MSXML) 3.0 in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows S XML Core Services (aka MSXML) 3.0 in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (system-state corruption) via crafted XML cont
nvd
CVE-2018-8225P3HIGHCVSS 8.1vr2-sp1v32-bit Systems Service Pack 2+4 more2018-06-14
CVE-2018-8225 [HIGH] CVE-2018-8225: A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it A remote code execution vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Wi
nvd
CVE-2010-0820P2HIGHCVSS 8.8vr22010-09-15
CVE-2010-0820 [HIGH] CWE-119 CVE-2010-0820: Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Act Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Application Mode (ADAM) in Windows XP SP2 and SP3 and Windows Server 2003 SP2; and Active Directory Lightweight Directory Service (AD LDS) in Wi
nvd
CVE-2014-1817P3CRITICALCVSS 9.3vr22014-06-11
CVE-2014-1817 [CRITICAL] CWE-119 CVE-2014-1817: usp10.dll in Uniscribe (aka the Unicode Script Processor) in Microsoft Windows Server 2003 SP2, Wind usp10.dll in Uniscribe (aka the Unicode Script Processor) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP1 and SP2, Live Meeting 2007 Console, Lync 2010 and 2013, Lync 2010 Attendee
nvd
CVE-2024-38104P2HIGHCVSS 8.8vr22024-07-09
CVE-2024-38104 [HIGH] CWE-822 CVE-2024-38104: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-38116P2HIGHCVSS 8.8vr22024-08-13
CVE-2024-38116 [HIGH] CWE-122 CVE-2024-38116: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-43611P2HIGHCVSS 8.8vr22024-10-08
CVE-2024-43611 [HIGH] CWE-20 CVE-2024-43611: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-49080P2HIGHCVSS 8.8vr22024-12-12
CVE-2024-49080 [HIGH] CWE-122 CVE-2024-49080: Windows IP Routing Management Snapin Remote Code Execution Vulnerability Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2025-21376P3HIGHCVSS 8.1vr22025-02-11
CVE-2025-21376 [HIGH] CWE-122 CVE-2025-21376: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2018-1004P3HIGHCVSS 8.8vr22018-04-12
CVE-2018-1004 [HIGH] CWE-787 CVE-2018-1004: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Internet Explorer 9, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10.
nvd
CVE-2026-20868P2HIGHCVSS 8.8vr22026-01-13
CVE-2026-20868 [HIGH] CWE-122 CVE-2026-20868: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-28220P3HIGHCVSS 8.1vr22023-04-11
CVE-2023-28220 [HIGH] CWE-591 CVE-2023-28220: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2023-28219P3HIGHCVSS 8.1vr22023-04-11
CVE-2023-28219 [HIGH] CWE-591 CVE-2023-28219: Layer 2 Tunneling Protocol Remote Code Execution Vulnerability Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2021-38666P2HIGHCVSS 8.8vr22021-11-10
CVE-2021-38666 [HIGH] CVE-2021-38666: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2015-1756P3CRITICALCVSS 9.3vr22015-06-10
CVE-2015-1756 [CRITICAL] CWE-416 CVE-2015-1756: Use-after-free vulnerability in Microsoft Common Controls in Microsoft Windows Vista SP2, Windows Se Use-after-free vulnerability in Microsoft Common Controls in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted web site that is accessed with the F12 Develope
nvd
CVE-2018-8346P3HIGHCVSS 8.8vr2-sp12018-08-15
CVE-2018-8346 [HIGH] CVE-2018-8346: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8345.
nvd
CVE-2024-43454P3HIGHCVSS 7.1vr2vsp22024-09-10
CVE-2024-43454 [HIGH] CWE-23 CVE-2024-43454: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2019-0793P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0793 [HIGH] CVE-2019-0793: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0795.
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase