cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 61 of 152
CVE-2025-62474P3HIGHCVSS 7.8vr22025-12-09
CVE-2025-62474 [HIGH] CWE-284 CVE-2025-62474: Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
nvd
CVE-2019-0582P3HIGHCVSS 7.8vr2-sp12019-01-08
CVE-2019-0582 [HIGH] CVE-2019-0582: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2010-3223P3HIGHCVSS 7.5vr22010-10-13
CVE-2010-3223 [HIGH] CWE-264 CVE-2010-3223: The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Dis
nvd
CVE-2023-35309P3HIGHCVSS 7.5vr22023-07-11
CVE-2023-35309 [HIGH] CWE-591 CVE-2023-35309: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2020-1153P3HIGHCVSS 7.8vr22020-05-21
CVE-2020-1153 [HIGH] CVE-2020-1153: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2020-0907P3HIGHCVSS 7.8vr22020-04-15
CVE-2020-0907 [HIGH] CVE-2020-0907: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
nvd
CVE-2022-35756P3HIGHCVSS 7.8vr22023-05-31
CVE-2022-35756 [HIGH] CVE-2022-35756: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2015-2430P3CRITICALCVSS 9.3vr22015-08-15
CVE-2015-2430 [CRITICAL] CWE-264 CVE-2015-2430: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow attackers to bypass an application sandbox protection mechanism and perform unspecified filesystem actions via a crafted application, aka "Windows Filesystem Elevation of Privilege
nvd
CVE-2009-3678P3CRITICALCVSS 9.3vr22010-05-14
CVE-2009-3678 [CRITICAL] CWE-189 CVE-2009-3678: Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing af
nvd
CVE-2024-30025P3HIGHCVSS 7.8vr22024-05-14
CVE-2024-30025 [HIGH] CWE-125 CVE-2024-30025: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2019-0879P3HIGHCVSS 7.8vr22019-04-09
CVE-2019-0879 [HIGH] CVE-2019-0879: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0877.
nvd
CVE-2018-0959P3HIGHCVSS 7.6vr2vx64-based Systems Service Pack 2+1 more2018-05-09
CVE-2018-0959 [HIGH] CWE-20 CVE-2018-0959: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2023-28244P3HIGHCVSS 8.1vr22023-04-11
CVE-2023-28244 [HIGH] CWE-327 CVE-2023-28244: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-37966P3HIGHCVSS 8.1vr22022-11-09
CVE-2022-37966 [HIGH] CVE-2022-37966: Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
nvd
CVE-2019-1484P3HIGHCVSS 7.8vr22019-12-10
CVE-2019-1484 [HIGH] CWE-20 CVE-2019-1484: A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate u A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
nvd
CVE-2020-0738P3HIGHCVSS 8.8vr22020-02-11
CVE-2020-0738 [HIGH] CWE-787 CVE-2020-0738: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
nvd
CVE-2020-1239P3HIGHCVSS 8.8vr22020-06-09
CVE-2020-1239 [HIGH] CVE-2020-1239: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1238.
nvd
CVE-2011-0032P3CRITICALCVSS 9.3vr22011-03-09
CVE-2011-0032 [CRITICAL] CVE-2011-0032: Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Reco
nvd
CVE-2022-41109P3HIGHCVSS 7.8vr22022-11-09
CVE-2022-41109 [HIGH] CVE-2022-41109: Windows Win32k Elevation of Privilege Vulnerability Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2017-11780P3HIGHCVSS 7.0vr22017-10-13
CVE-2017-11780 [HIGH] CVE-2017-11780: The Server Message Block 1.0 (SMBv1) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, The Server Message Block 1.0 (SMBv1) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a remote code execution vulnerability when it fails to properly handle certain requests, aka "Windows SMB Remote Code Execution
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase