cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 30 of 152
CVE-2013-5056P3CRITICALCVSS 9.3vr22013-12-11
CVE-2013-5056 [CRITICAL] CWE-416 CVE-2013-5056: Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a deni
nvd
CVE-2016-0009P3HIGHCVSS 8.8vr22016-01-13
CVE-2016-0009 [HIGH] CWE-264 CVE-2016-0009: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via unspecified vectors, aka "Win32k Remote Code Execution Vulnerability."
nvd
CVE-2017-0272P3HIGHCVSS 8.1vr22017-05-12
CVE-2017-0272 [HIGH] CVE-2017-0272: The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution
nvd
CVE-2019-1384P3CRITICALCVSS 9.9vr22019-11-12
CVE-2019-1384 [CRITICAL] CWE-522 CVE-2019-1384: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the sessio A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.
nvd
CVE-2022-29129P3HIGHCVSS 8.8vr22022-05-10
CVE-2022-29129 [HIGH] CVE-2022-29129: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29128P3HIGHCVSS 8.8vr22022-05-10
CVE-2022-29128 [HIGH] CVE-2022-29128: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29131P3HIGHCVSS 8.8vr22022-05-10
CVE-2022-29131 [HIGH] CVE-2022-29131: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29141P3HIGHCVSS 8.8vr22022-05-10
CVE-2022-29141 [HIGH] CVE-2022-29141: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2018-8475P3HIGHCVSS 8.8vr2-sp1v32-bit Systems Service Pack 2+4 more2018-09-13
CVE-2018-8475 [HIGH] CVE-2018-8475: A remote code execution vulnerability exists when Windows does not properly handle specially crafted A remote code execution vulnerability exists when Windows does not properly handle specially crafted image files, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2020-1299P3HIGHCVSS 8.8vr22020-06-09
CVE-2020-1299 [HIGH] CVE-2020-1299: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2015-2473P3CRITICALCVSS 9.3vr22015-08-15
CVE-2015-2473 [CRITICAL] CVE-2015-2473: Untrusted search path vulnerability in the client in Remote Desktop Protocol (RDP) through 8.1 in Mi Untrusted search path vulnerability in the client in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Protocol DLL Planting Remote Code
nvd
CVE-2019-0765P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0765 [HIGH] CWE-787 CVE-2019-0765: A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution Vulnerability'.
nvd
CVE-2025-26647P2HIGHCVSS 8.8vr22025-04-08
CVE-2025-26647 [HIGH] CWE-20 CVE-2025-26647: Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges ov Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2011-1975P3CRITICALCVSS 9.3vr22011-08-10
CVE-2011-1975 [CRITICAL] CVE-2011-1975: Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Comp Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an Excel .xlsx file,
nvd
CVE-2020-1435P3HIGHCVSS 8.8vr22020-07-14
CVE-2020-1435 [HIGH] CVE-2020-1435: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
nvd
CVE-2019-0756P3HIGHCVSS 8.8vr22019-04-09
CVE-2019-0756 [HIGH] CWE-611 CVE-2019-0756: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
nvd
CVE-2019-1291P3HIGHCVSS 8.8vr22019-09-11
CVE-2019-1291 [HIGH] CVE-2019-1291: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1290.
nvd
CVE-2019-1290P3HIGHCVSS 8.8vr22019-09-11
CVE-2019-1290 [HIGH] CVE-2019-1290: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connec A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1291.
nvd
CVE-2019-0736P3CRITICALCVSS 9.8vr22019-08-14
CVE-2019-0736 [CRITICAL] CWE-787 CVE-2019-0736: A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client. An attacker who successfully exploited the vulnerability could run arbitrary code on the client machine. To exploit the vulnerability, an attacker could send specially crafted DHCP responses to a client. The securi
nvd
CVE-2019-1441P3HIGHCVSS 8.8vr22019-11-12
CVE-2019-1441 [HIGH] CWE-119 CVE-2019-1441: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase