cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 49 of 152
CVE-2018-8553P3HIGHCVSS 7.8vr2-sp1v32-bit Systems Service Pack 2+4 more2018-11-14
CVE-2018-8553 [HIGH] CVE-2018-8553: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 1
nvd
CVE-2019-1280P3HIGHCVSS 7.8vr22019-09-11
CVE-2019-1280 [HIGH] CWE-59 CVE-2019-1280: A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execu A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
nvd
CVE-2020-1317P3HIGHCVSS 8.8vr22020-06-09
CVE-2020-1317 [HIGH] CVE-2020-1317: An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Grou An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege Vulnerability'.
nvd
CVE-2025-62458P3HIGHCVSS 7.8vr22025-12-09
CVE-2025-62458 [HIGH] CWE-122 CVE-2025-62458: Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privile Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
nvd
CVE-2023-36903P3CRITICALCVSS 9.8vr22023-08-08
CVE-2023-36903 [CRITICAL] CWE-59 CVE-2023-36903: Windows System Assessment Tool Elevation of Privilege Vulnerability Windows System Assessment Tool Elevation of Privilege Vulnerability
nvd
CVE-2026-20929P3HIGHCVSS 7.5vr2-sp12026-01-13
CVE-2026-20929 [HIGH] CWE-284 CVE-2026-20929: Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-26158P3HIGHCVSS 7.8vr22024-04-09
CVE-2024-26158 [HIGH] CWE-59 CVE-2024-26158: Microsoft Install Service Elevation of Privilege Vulnerability Microsoft Install Service Elevation of Privilege Vulnerability
nvd
CVE-2026-20849P3HIGHCVSS 7.5vr2-sp12026-01-13
CVE-2026-20849 [HIGH] CWE-807 CVE-2026-20849: Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacke Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-36900P3HIGHCVSS 7.8vr22023-08-08
CVE-2023-36900 [HIGH] CWE-190 CVE-2023-36900: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-1400P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1400 [HIGH] CWE-191 CVE-2020-1400: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1401, CVE-2020-1407.
nvd
CVE-2022-24502P3MEDIUMCVSS 6.5vr22022-03-09
CVE-2022-24502 [MEDIUM] CVE-2022-24502: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2022-24492P3HIGHCVSS 8.8vr22022-04-15
CVE-2022-24492 [HIGH] CVE-2022-24492: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-38034P3HIGHCVSS 8.8vr22022-10-11
CVE-2022-38034 [HIGH] CVE-2022-38034: Windows Workstation Service Elevation of Privilege Vulnerability Windows Workstation Service Elevation of Privilege Vulnerability
nvd
CVE-2019-1006P3HIGHCVSS 7.5vr22019-07-15
CVE-2019-1006 [HIGH] CWE-295 CVE-2019-1006: An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
nvd
CVE-2022-23253P3MEDIUMCVSS 6.5vr22022-03-09
CVE-2022-23253 [MEDIUM] CVE-2022-23253: Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
nvd
CVE-2022-22019P3HIGHCVSS 8.8vr2vsp22022-05-10
CVE-2022-22019 [HIGH] CVE-2022-22019: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-21857P3HIGHCVSS 8.8vr22022-01-11
CVE-2022-21857 [HIGH] CVE-2022-21857: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2023-35359P3HIGHCVSS 7.8vr22023-08-08
CVE-2023-35359 [HIGH] CWE-23 CVE-2023-35359: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-24528P3HIGHCVSS 8.8vr22022-04-15
CVE-2022-24528 [HIGH] CVE-2022-24528: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2021-33750P3HIGHCVSS 8.8vr22021-07-14
CVE-2021-33750 [HIGH] CVE-2021-33750: Windows DNS Snap-in Remote Code Execution Vulnerability Windows DNS Snap-in Remote Code Execution Vulnerability
nvd