Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 68 of 152
CVE-2020-1407P3HIGHCVSS 7.8vr22020-07-14
CVE-2020-1407 [HIGH] CVE-2020-1407: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1400, CVE-2020-1401.
nvd
CVE-2010-3966P3CRITICALCVSS 9.3vr22010-12-16
CVE-2010-3966 [CRITICAL] CVE-2010-3966: Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCa
Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS file, or a WPOST file, aka "BranchCache Insecure Library Loading Vulnerability."
nvd
CVE-2014-0316P3HIGHCVSS 7.5vr22014-08-12
CVE-2014-0316 [HIGH] CWE-399 CVE-2014-0316: Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server
Memory leak in the Local RPC (LRPC) server implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (memory consumption) and bypass the ASLR protection mechanism via a crafted client that sends messages
nvd
CVE-2014-6317P3HIGHCVSS 7.1vr22014-11-11
CVE-2014-6317 [HIGH] CWE-129 CVE-2014-6317: Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Win
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font, aka "Denial
nvd
CVE-2022-22000P3HIGHCVSS 7.8vr22022-02-09
CVE-2022-22000 [HIGH] CVE-2022-22000: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2011-1869P3HIGHCVSS 7.8vr22011-06-16
CVE-2011-1869 [HIGH] CWE-399 CVE-2011-1869: The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server
The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability.
nvd
CVE-2017-8495P3HIGHCVSS 7.5vr22017-07-11
CVE-2017-8495 [HIGH] CWE-287 CVE-2017-8495: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to bypass Extended Protection for Authentication when Kerberos fails to prevent tampering with the SNAME field during ticket exchange, aka "Kerberos SNA
nvd
CVE-2023-21812P3HIGHCVSS 7.8vr22023-02-14
CVE-2023-21812 [HIGH] CWE-122 CVE-2023-21812: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-22026P3HIGHCVSS 8.8vr22022-07-12
CVE-2022-22026 [HIGH] CWE-787 CVE-2022-22026: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2017-8588P3HIGHCVSS 7.0vr22017-07-11
CVE-2017-8588 [HIGH] CVE-2017-8588: Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
Microsoft WordPad in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it parses specially crafted files, aka "WordPad Remote Code Execution Vulnerability".
nvd
CVE-2017-8633P3HIGHCVSS 7.5vr22017-08-08
CVE-2017-8633 [HIGH] CWE-863 CVE-2017-8633: Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win
Windows Error Reporting (WER) in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability, aka "Windows Error Reporting Elevation of Privilege Vulnerability".
nvd
CVE-2022-21843P3HIGHCVSS 7.5vr22022-01-11
CVE-2022-21843 [HIGH] CVE-2022-21843: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2023-36425P3HIGHCVSS 8.0vr22023-11-14
CVE-2023-36425 [HIGH] CWE-122 CVE-2023-36425: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2022-22037P3HIGHCVSS 7.5vr22022-07-12
CVE-2022-22037 [HIGH] CVE-2022-22037: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2021-43233P3HIGHCVSS 7.5vr22021-12-15
CVE-2021-43233 [HIGH] CVE-2021-43233: Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
nvd
CVE-2025-26641P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-26641 [HIGH] CWE-400 CVE-2025-26641: Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker
Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2022-30142P3HIGHCVSS 7.5vr22022-06-15
CVE-2022-30142 [HIGH] CVE-2022-30142: Windows File History Remote Code Execution Vulnerability
Windows File History Remote Code Execution Vulnerability
nvd
CVE-2016-7257P3MEDIUMCVSS 6.5vr22016-12-20
CVE-2016-7257 [MEDIUM] CWE-200 CVE-2016-7257: The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,
The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
nvd
CVE-2022-21983P3HIGHCVSS 7.5vr22022-04-15
CVE-2022-21983 [HIGH] CVE-2022-21983: Win32 Stream Enumeration Remote Code Execution Vulnerability
Win32 Stream Enumeration Remote Code Execution Vulnerability
nvd
CVE-2017-11788P3HIGHCVSS 7.5vr22017-11-15
CVE-2017-11788 [HIGH] CVE-2017-11788: Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows
Windows Search in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows server, version 1709 allows an unauthenticated attacker to remotely send specially crafted messages that could cause a denial of service against the system due to i
nvd