Microsoft Windows Server 2008 vulnerabilities

3,038 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,038
CISA KEV
133
actively exploited
Public exploits
313
Exploited in wild
132
Severity breakdown
CRITICAL180HIGH1977MEDIUM842LOW39

Vulnerabilities

Page 5 of 152
CVE-2025-55700MEDIUMCVSS 4.3vr22025-10-14
CVE-2025-55700 [MEDIUM] CWE-125 CVE-2025-55700: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-59214MEDIUMCVSS 6.5vr22025-10-14
CVE-2025-59214 [MEDIUM] CWE-200 CVE-2025-59214: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-58739MEDIUMCVSS 6.5vr22025-10-14
CVE-2025-58739 [MEDIUM] CWE-200 CVE-2025-58739: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2025-59190MEDIUMCVSS 5.5vr22025-10-14
CVE-2025-59190 [MEDIUM] CWE-20 CVE-2025-59190: Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to d Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2025-58729MEDIUMCVSS 6.5vr22025-10-14
CVE-2025-58729 [MEDIUM] CWE-1287 CVE-2025-58729: Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an auth Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network.
nvd
CVE-2025-59280LOWCVSS 3.1vr22025-10-14
CVE-2025-59280 [LOW] CWE-287 CVE-2025-59280: Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering o Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
nvd
CVE-2025-55695LOWCVSS 3.3vr22025-10-14
CVE-2025-55695 [LOW] CWE-125 CVE-2025-55695: Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose inf Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
nvd
CVE-2025-55234CRITICALCVSS 9.8vr22025-09-09
CVE-2025-55234 [CRITICAL] CWE-287 CVE-2025-55234: SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who suc SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extend
nvd
CVE-2025-54093HIGHCVSS 7.0vr22025-09-09
CVE-2025-54093 [HIGH] CWE-367 CVE-2025-54093: Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54113HIGHCVSS 8.8vr22025-09-09
CVE-2025-54113 [HIGH] CWE-122 CVE-2025-54113: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-54895HIGHCVSS 7.8vr22025-09-09
CVE-2025-54895 [HIGH] CWE-190 CVE-2025-54895: Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54110HIGHCVSS 8.8vr22025-09-09
CVE-2025-54110 [HIGH] CWE-190 CVE-2025-54110: Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54099HIGHCVSS 7.0vr22025-09-09
CVE-2025-54099 [HIGH] CWE-121 CVE-2025-54099: Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized at Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54918HIGHCVSS 8.8vr22025-09-09
CVE-2025-54918 [HIGH] CWE-287 CVE-2025-54918: Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a n Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2025-54894HIGHCVSS 7.8vr22025-09-09
CVE-2025-54894 [HIGH] CWE-122 CVE-2025-54894: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2025-54916HIGHCVSS 7.8vr22025-09-09
CVE-2025-54916 [HIGH] CWE-121 CVE-2025-54916: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2025-54911HIGHCVSS 7.3vr22025-09-09
CVE-2025-54911 [HIGH] CWE-416 CVE-2025-54911: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54912HIGHCVSS 7.8vr22025-09-09
CVE-2025-54912 [HIGH] CWE-416 CVE-2025-54912: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally. Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54098HIGHCVSS 7.8vr22025-09-09
CVE-2025-54098 [HIGH] CWE-284 CVE-2025-54098: Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges local Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-53798MEDIUMCVSS 6.5vr22025-09-09
CVE-2025-53798 [MEDIUM] CWE-126 CVE-2025-53798: Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd