Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 63 of 152
CVE-2022-30140P3HIGHCVSS 7.5vr22022-06-15
CVE-2022-30140 [HIGH] CVE-2022-30140: Windows iSCSI Discovery Service Remote Code Execution Vulnerability
Windows iSCSI Discovery Service Remote Code Execution Vulnerability
nvd
CVE-2024-30022P3HIGHCVSS 7.5vr22024-05-14
CVE-2024-30022 [HIGH] CWE-197 CVE-2024-30022: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30024P3HIGHCVSS 7.5vr22024-05-14
CVE-2024-30024 [HIGH] CWE-197 CVE-2024-30024: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-30023P3HIGHCVSS 7.5vr22024-05-14
CVE-2024-30023 [HIGH] CWE-197 CVE-2024-30023: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-26195P3HIGHCVSS 7.2vr22024-04-09
CVE-2024-26195 [HIGH] CWE-122 CVE-2024-26195: DHCP Server Service Remote Code Execution Vulnerability
DHCP Server Service Remote Code Execution Vulnerability
nvd
CVE-2025-32713P3HIGHCVSS 7.8vr22025-06-10
CVE-2025-32713 [HIGH] CWE-122 CVE-2025-32713: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-24474P3HIGHCVSS 7.8vr22022-04-15
CVE-2022-24474 [HIGH] CVE-2022-24474: Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
nvd
CVE-2019-1246P3HIGHCVSS 7.8vr22019-09-11
CVE-2019-1246 [HIGH] CVE-2019-1246: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249, CVE-2019-1250.
nvd
CVE-2016-3342P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-3342 [HIGH] CVE-2016-3342: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3340P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-3340 [HIGH] CVE-2016-3340: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2016-3343P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-3343 [HIGH] CVE-2016-3343: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of
nvd
CVE-2024-38028P3HIGHCVSS 7.2vr22024-07-09
CVE-2024-38028 [HIGH] CWE-125 CVE-2024-38028: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2024-38025P3HIGHCVSS 7.2vr22024-07-09
CVE-2024-38025 [HIGH] CWE-122 CVE-2024-38025: Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
Microsoft Windows Performance Data Helper Library Remote Code Execution Vulnerability
nvd
CVE-2025-50173P3HIGHCVSS 7.8vr22025-08-12
CVE-2025-50173 [HIGH] CWE-1390 CVE-2025-50173: Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally
Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2019-1406P3HIGHCVSS 7.8vr22019-11-12
CVE-2019-1406 [HIGH] CVE-2019-1406: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'.
nvd
CVE-2023-36401P3HIGHCVSS 7.2vr2vsp22023-11-14
CVE-2023-36401 [HIGH] CWE-190 CVE-2023-36401: Microsoft Remote Registry Service Remote Code Execution Vulnerability
Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2025-59201P3HIGHCVSS 7.8vr22025-10-14
CVE-2025-59201 [HIGH] CWE-284 CVE-2025-59201: Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker
Improper access control in Network Connection Status Indicator (NCSI) allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-62571P3HIGHCVSS 7.8vr22025-12-09
CVE-2025-62571 [HIGH] CWE-20 CVE-2025-62571: Improper input validation in Windows Installer allows an authorized attacker to elevate privileges l
Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2016-0128P3MEDIUMCVSS 6.8vr22016-04-12
CVE-2016-0128 [MEDIUM] CWE-254 CVE-2016-0128: The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 an
The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate
nvd
CVE-2025-59277P3HIGHCVSS 7.8vr22025-10-14
CVE-2025-59277 [HIGH] CWE-1287 CVE-2025-59277: Improper validation of specified type of input in Windows Authentication Methods allows an authorize
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd