Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 39 of 152
CVE-2017-0220P4MEDIUMCVSS 4.7PoCvr22017-05-12
CVE-2017-0220 [MEDIUM] CVE-2017-0220: The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gol
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a different vulnerability than CVE-2017-0175, CVE-2017-0258, and CVE-2017-0259.
nvd
CVE-2017-0258P4MEDIUMCVSS 4.7PoCvr22017-05-12
CVE-2017-0258 [MEDIUM] CVE-2017-0258: The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows authenticated attackers to obtain sensitive information via a specially crafted document, aka "Windows Kernel Information Disclosure Vulnerability," a
nvd
CVE-2023-35381P3HIGHCVSS 8.8vr22023-08-08
CVE-2023-35381 [HIGH] CWE-190 CVE-2023-35381: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2023-21727P3HIGHCVSS 8.8vr22023-04-11
CVE-2023-21727 [HIGH] CWE-122 CVE-2023-21727: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2024-38128P3HIGHCVSS 8.8vr22024-08-13
CVE-2024-38128 [HIGH] CWE-190 CVE-2024-38128: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38121P3HIGHCVSS 8.8vr22024-08-13
CVE-2024-38121 [HIGH] CWE-122 CVE-2024-38121: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38115P3HIGHCVSS 8.8vr22024-08-13
CVE-2024-38115 [HIGH] CWE-122 CVE-2024-38115: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-38130P3HIGHCVSS 8.8vr22024-08-13
CVE-2024-38130 [HIGH] CWE-122 CVE-2024-38130: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38120P3HIGHCVSS 8.8vr22024-08-13
CVE-2024-38120 [HIGH] CWE-122 CVE-2024-38120: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38154P3HIGHCVSS 8.8vr22024-08-13
CVE-2024-38154 [HIGH] CWE-122 CVE-2024-38154: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38114P3HIGHCVSS 8.8vr22024-08-13
CVE-2024-38114 [HIGH] CWE-122 CVE-2024-38114: Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
nvd
CVE-2024-49086P3HIGHCVSS 8.8vr22024-12-12
CVE-2024-49086 [HIGH] CWE-122 CVE-2024-49086: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-49085P3HIGHCVSS 8.8vr22024-12-12
CVE-2024-49085 [HIGH] CWE-122 CVE-2024-49085: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-27477P3HIGHCVSS 8.8vr22025-04-08
CVE-2025-27477 [HIGH] CWE-122 CVE-2025-27477: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-1125P3MEDIUMCVSS 5.6PoCvr22019-09-03
CVE-2019-1125 [MEDIUM] CVE-2019-1125: An information disclosure vulnerability exists when certain central processing units (CPU) speculati
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The v
nvd
CVE-2024-43622P3HIGHCVSS 8.8vr22024-11-12
CVE-2024-43622 [HIGH] CWE-122 CVE-2024-43622: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-43620P3HIGHCVSS 8.8vr22024-11-12
CVE-2024-43620 [HIGH] CWE-122 CVE-2024-43620: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-43621P3HIGHCVSS 8.8vr22024-11-12
CVE-2024-43621 [HIGH] CWE-122 CVE-2024-43621: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2024-49125P3HIGHCVSS 8.8vr22024-12-12
CVE-2024-49125 [HIGH] CWE-122 CVE-2024-49125: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-21303P3HIGHCVSS 8.8vr22025-01-14
CVE-2025-21303 [HIGH] CWE-122 CVE-2025-21303: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd