cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 3 of 152
CVE-2020-1054P1HIGHCVSS 7.8KEVPoCvr22020-05-21
CVE-2020-1054 [HIGH] CWE-787 CVE-2020-1054: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
nvd
CVE-2013-3660P1HIGHCVSS 7.8KEVPoCRansomwarevr22013-05-24
CVE-2013-3660 [HIGH] CWE-119 CVE-2013-3660: The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows X The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obta
nvd
CVE-2020-0787P1HIGHCVSS 7.8KEVPoCRansomwarevr22020-03-12
CVE-2020-0787 [HIGH] CWE-59 CVE-2020-0787: An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Serv An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
nvd
CVE-2022-37969P1HIGHCVSS 7.8KEVPoCRansomwarevr22022-09-13
CVE-2022-37969 [HIGH] CWE-787 CVE-2022-37969: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2016-0099P1HIGHCVSS 7.8KEVPoCRansomwarevr22016-03-09
CVE-2016-0099 [HIGH] CWE-120 CVE-2016-0099: The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privi
nvd
CVE-2025-24054P1MEDIUMCVSS 5.4KEVPoCvr22025-03-11
CVE-2025-24054 [MEDIUM] CWE-73 CVE-2025-24054: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spo External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-30397P1HIGHCVSS 7.5KEVPoCvr22025-05-13
CVE-2025-30397 [HIGH] CWE-843 CVE-2025-30397: Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows a Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-29824P1HIGHCVSS 7.8KEVPoCRansomwarevr22025-04-08
CVE-2025-29824 [HIGH] CWE-416 CVE-2025-29824: Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate pri Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-36874P1HIGHCVSS 7.8KEVPoCvr22023-07-11
CVE-2023-36874 [HIGH] CWE-59 CVE-2023-36874: Windows Error Reporting Service Elevation of Privilege Vulnerability Windows Error Reporting Service Elevation of Privilege Vulnerability
nvd
CVE-2019-1405P1HIGHCVSS 7.8KEVPoCRansomwarevr22019-11-12
CVE-2019-1405 [HIGH] CWE-269 CVE-2019-1405: An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) servi An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
nvd
CVE-2025-26633P1HIGHCVSS 7.0KEVPoCRansomwarevr22025-03-11
CVE-2025-26633 [HIGH] CWE-707 CVE-2025-26633: Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2018-8639P1HIGHCVSS 7.8KEVPoCRansomwarevr2vr2-sp1+5 more2018-12-12
CVE-2018-8639 [HIGH] CWE-404 CVE-2018-8639: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server
nvd
CVE-2016-3309P1HIGHCVSS 7.8KEVPoCRansomwarevr22016-08-09
CVE-2016-3309 [HIGH] CVE-2016-3309: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308
nvd
CVE-2021-41379P1HIGHCVSS 7.8KEVPoCRansomwarevr22021-11-10
CVE-2021-41379 [HIGH] CWE-59 CVE-2021-41379: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2024-49138P1HIGHCVSS 7.8KEVPoCvr2vsp22024-12-12
CVE-2024-49138 [HIGH] CWE-122 CVE-2024-49138: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-1215P1HIGHCVSS 7.8KEVPoCRansomwarevr22019-09-11
CVE-2019-1215 [HIGH] CWE-269 CVE-2019-1215: An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.
nvd
CVE-2024-35250P1HIGHCVSS 7.8KEVPoCvr2-sp12024-06-11
CVE-2024-35250 [HIGH] CWE-822 CVE-2024-35250: Windows Kernel-Mode Driver Elevation of Privilege Vulnerability Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
nvd
CVE-2018-8440P1HIGHCVSS 7.8KEVPoCRansomwarevr2-sp1v32-bit Systems Service Pack 2+4 more2018-09-13
CVE-2018-8440 [HIGH] CVE-2018-8440: An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Loc An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows ALPC Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Wind
nvd
CVE-2024-38193P1HIGHCVSS 7.8KEVPoCvr22024-08-13
CVE-2024-38193 [HIGH] CWE-416 CVE-2024-38193: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-24521P1HIGHCVSS 7.8KEVPoCRansomwarevr22022-04-15
CVE-2022-24521 [HIGH] CWE-787 CVE-2022-24521: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase