cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 58 of 152
CVE-2011-1267P3HIGHCVSS 7.8vr22011-06-16
CVE-2011-1267 [HIGH] CWE-399 CVE-2011-1267: The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1 The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
nvd
CVE-2017-0158P3HIGHCVSS 7.5vr22017-04-12
CVE-2017-0158 [HIGH] CVE-2017-0158: An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."
nvd
CVE-2026-0386P3HIGHCVSS 7.5vr22026-01-13
CVE-2026-0386 [HIGH] CWE-284 CVE-2026-0386: Improper access control in Windows Deployment Services allows an unauthorized attacker to execute co Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-60704P3HIGHCVSS 7.5vr22025-11-11
CVE-2025-60704 [HIGH] CWE-325 CVE-2025-60704: Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2012-0152P3MEDIUMCVSS 4.3vr22012-03-13
CVE-2012-0152 [MEDIUM] CWE-20 CVE-2012-0152: The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
nvd
CVE-2020-0665P3HIGHCVSS 8.1vr22020-02-11
CVE-2020-0665 [HIGH] CVE-2020-0665: An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default se An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.
nvd
CVE-2019-0734P3HIGHCVSS 8.1vr22019-05-16
CVE-2019-0734 [HIGH] CVE-2019-0734: An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacke An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and replace authentication request using Kerberos, allowing an attacker to be validated as an Administrator.The update addresses this vulnerability by changing how these requests are validated., aka 'Windows Elevation of Privilege
nvd
CVE-2015-2429P3CRITICALCVSS 9.3vr22015-08-15
CVE-2015-2429 [CRITICAL] CWE-264 CVE-2015-2429: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow attackers to bypass an application sandbox protection mechanism and perform unspecified registry actions via a crafted application, aka "Windows Registry Elevation of Privilege Vul
nvd
CVE-2021-31971P3HIGHCVSS 8.8vr2vsp22021-06-08
CVE-2021-31971 [HIGH] CVE-2021-31971: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2020-1031P3HIGHCVSS 7.5vr22020-09-11
CVE-2020-1031 [HIGH] CVE-2020-1031: <p>An information disclosure vulnerability exists in the way that the Windows Server DHCP service im An information disclosure vulnerability exists in the way that the Windows Server DHCP service improperly discloses the contents of its memory. To exploit the vulnerability, an unauthenticated attacker could send a specially crafted packet to an affected DHCP server. An attacker who successfully exploited this vulnerability could obtain information to further c
nvd
CVE-2024-43623P3HIGHCVSS 7.8vr22024-11-12
CVE-2024-43623 [HIGH] CWE-190 CVE-2024-43623: Windows NT OS Kernel Elevation of Privilege Vulnerability Windows NT OS Kernel Elevation of Privilege Vulnerability
nvd
CVE-2021-34446P3HIGHCVSS 8.8vr22021-07-16
CVE-2021-34446 [HIGH] CVE-2021-34446: Windows HTML Platforms Security Feature Bypass Vulnerability Windows HTML Platforms Security Feature Bypass Vulnerability
nvd
CVE-2024-38124P3CRITICALCVSS 9.0vr22024-10-08
CVE-2024-38124 [CRITICAL] CWE-287 CVE-2024-38124: Windows Netlogon Elevation of Privilege Vulnerability Windows Netlogon Elevation of Privilege Vulnerability
nvd
CVE-2019-0851P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0851 [HIGH] CVE-2019-0851: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0877, CVE-2019-0879.
nvd
CVE-2019-0846P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0846 [HIGH] CVE-2019-0846: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0847, CVE-2019-0851, CVE-2019-0877, CVE-2019-0879.
nvd
CVE-2019-0847P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0847 [HIGH] CVE-2019-0847: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0851, CVE-2019-0877, CVE-2019-0879.
nvd
CVE-2022-37975P3HIGHCVSS 8.8vr22022-10-11
CVE-2022-37975 [HIGH] CVE-2022-37975: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2011-1991P3CRITICALCVSS 9.3vr22011-09-15
CVE-2011-1991 [CRITICAL] CVE-2011-1991: Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2 Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt fi
nvd
CVE-2022-24542P3HIGHCVSS 7.8vr22022-04-15
CVE-2022-24542 [HIGH] CVE-2022-24542: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2024-49105P3HIGHCVSS 8.4vr22024-12-12
CVE-2024-49105 [HIGH] CWE-284 CVE-2024-49105: Remote Desktop Client Remote Code Execution Vulnerability Remote Desktop Client Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase