cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 37 of 152
CVE-2025-60715P3HIGHCVSS 8.0vr22025-11-11
CVE-2025-60715 [HIGH] CWE-122 CVE-2025-60715: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2020-17042P3HIGHCVSS 8.8vr22020-11-11
CVE-2020-17042 [HIGH] CVE-2020-17042: Windows Print Spooler Remote Code Execution Vulnerability Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2023-36434P3CRITICALCVSS 9.8vr22023-10-10
CVE-2023-36434 [CRITICAL] CWE-307 CVE-2023-36434: Windows IIS Server Elevation of Privilege Vulnerability Windows IIS Server Elevation of Privilege Vulnerability
nvd
CVE-2020-1061P3HIGHCVSS 8.8vr22020-05-21
CVE-2020-1061 [HIGH] CWE-787 CVE-2020-1061: A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles ob A remote code execution vulnerability exists in the way that the Microsoft Script Runtime handles objects in memory, aka 'Microsoft Script Runtime Remote Code Execution Vulnerability'.
nvd
CVE-2016-0038P3HIGHCVSS 7.8vr22016-02-10
CVE-2016-0038 [HIGH] CWE-119 CVE-2016-0038: Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journal Memory Corruption Vulnerability."
nvd
CVE-2017-0161P3HIGHCVSS 8.1vr22017-09-13
CVE-2017-0161 [HIGH] CWE-362 CVE-2017-0161: The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, The Windows NetBT Session Services component on Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to maintain certain sequencing requirements, aka "NetBIOS Remote Code
nvd
CVE-2015-6100P3MEDIUMCVSS 6.9PoCvr22015-11-11
CVE-2015-6100 [MEDIUM] CWE-264 CVE-2015-6100: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulne
nvd
CVE-2022-22029P3HIGHCVSS 8.1vr22022-07-12
CVE-2022-22029 [HIGH] CVE-2022-22029: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2017-0250P3HIGHCVSS 7.8vr22017-08-08
CVE-2017-0250 [HIGH] CWE-119 CVE-2017-0250: Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to buffer overflow, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability".
nvd
CVE-2021-1674P3HIGHCVSS 8.8vr22021-01-12
CVE-2021-1674 [HIGH] CVE-2021-1674: Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability Windows Remote Desktop Protocol Core Security Feature Bypass Vulnerability
nvd
CVE-2020-0684P3HIGHCVSS 8.8vr22020-03-12
CVE-2020-0684 [HIGH] CVE-2020-0684: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2022-21922P3HIGHCVSS 8.8vr22022-01-11
CVE-2022-21922 [HIGH] CVE-2022-21922: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28327P3HIGHCVSS 8.8vr22021-04-13
CVE-2021-28327 [HIGH] CVE-2021-28327: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28340P3HIGHCVSS 8.8vr22021-04-13
CVE-2021-28340 [HIGH] CVE-2021-28340: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28356P3HIGHCVSS 8.8vr22021-04-13
CVE-2021-28356 [HIGH] CVE-2021-28356: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28344P3HIGHCVSS 8.8vr22021-04-13
CVE-2021-28344 [HIGH] CVE-2021-28344: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28333P3HIGHCVSS 8.8vr22021-04-13
CVE-2021-28333 [HIGH] CVE-2021-28333: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28355P3HIGHCVSS 8.8vr22021-04-13
CVE-2021-28355 [HIGH] CVE-2021-28355: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28434P3HIGHCVSS 8.8vr22021-04-13
CVE-2021-28434 [HIGH] CVE-2021-28434: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-28335P3HIGHCVSS 8.8vr22021-04-13
CVE-2021-28335 [HIGH] CVE-2021-28335: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase