Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 65 of 152
CVE-2024-38258P3HIGHCVSS 7.5vr22024-09-10
CVE-2024-38258 [HIGH] CWE-23 CVE-2024-38258: Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
nvd
CVE-2024-29996P3HIGHCVSS 7.8vr22024-05-14
CVE-2024-29996 [HIGH] CWE-125 CVE-2024-29996: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-27737P3HIGHCVSS 8.6vr22025-04-08
CVE-2025-27737 [HIGH] CWE-20 CVE-2025-27737: Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass
Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2020-1208P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1208 [HIGH] CVE-2020-1208: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1236.
nvd
CVE-2009-3676P3HIGHCVSS 7.1vr22009-11-13
CVE-2009-3676 [HIGH] CWE-399 CVE-2009-3676: The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB ser
The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of
nvd
CVE-2023-29351P3HIGHCVSS 8.1vr22023-06-14
CVE-2023-29351 [HIGH] CWE-59 CVE-2023-29351: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-33647P3HIGHCVSS 8.1vr22022-09-13
CVE-2022-33647 [HIGH] CVE-2022-33647: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2025-24052P3HIGHCVSS 7.8vr22025-10-14
CVE-2025-24052 [HIGH] CWE-121 CVE-2025-24052: Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update.
Fax modem hardware dependent on this specific driver will no longer work on Window
nvd
CVE-2019-1057P3HIGHCVSS 7.5vr22019-08-14
CVE-2019-1057 [HIGH] CWE-611 CVE-2019-1057: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system.
To exploit the vulnerability, an attacker could host a specially crafted website designed to invoke MSXML thr
nvd
CVE-2024-29995P3HIGHCVSS 8.1vr22024-08-13
CVE-2024-29995 [HIGH] CWE-208 CVE-2024-29995: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2021-34442P3HIGHCVSS 7.5vr22021-07-16
CVE-2021-34442 [HIGH] CVE-2021-34442: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-26882P3HIGHCVSS 7.8vr22021-03-11
CVE-2021-26882 [HIGH] CVE-2021-26882: Remote Access API Elevation of Privilege Vulnerability
Remote Access API Elevation of Privilege Vulnerability
nvd
CVE-2023-23410P3HIGHCVSS 7.8vr22023-03-14
CVE-2023-23410 [HIGH] CWE-190 CVE-2023-23410: Windows HTTP.sys Elevation of Privilege Vulnerability
Windows HTTP.sys Elevation of Privilege Vulnerability
nvd
CVE-2015-0009P4LOWCVSS 3.3PoCvr22015-02-11
CVE-2015-0009 [LOW] CWE-254 CVE-2015-0009: The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2,
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing requirement and trigger a revert-to-default ac
nvd
CVE-2017-11781P3HIGHCVSS 7.5vr22017-10-13
CVE-2017-11781 [HIGH] CWE-20 CVE-2017-11781: The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7
The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a denial of service vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB D
nvd
CVE-2025-26673P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-26673 [HIGH] CWE-400 CVE-2025-26673: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-27469P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-27469 [HIGH] CWE-400 CVE-2025-27469: Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
nvd
CVE-2016-3348P3HIGHCVSS 7.8vr22016-09-14
CVE-2016-3348 [HIGH] CWE-264 CVE-2016-3348: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2020-1401P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1401 [HIGH] CVE-2020-1401: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1407.
nvd
CVE-2022-30149P3HIGHCVSS 7.5vr22022-06-15
CVE-2022-30149 [HIGH] CVE-2022-30149: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd