Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 7 of 152
CVE-2020-1027P1HIGHCVSS 7.8KEVvr22020-04-15
CVE-2020-1027 [HIGH] CVE-2020-1027: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.
nvd
CVE-2024-38217P2MEDIUMCVSS 5.4KEVvr22024-09-10
CVE-2024-38217 [MEDIUM] CWE-693 CVE-2024-38217: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2017-0001P1HIGHCVSS 7.8KEVvr22017-03-17
CVE-2017-0001 [HIGH] CVE-2017-0001: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is dif
nvd
CVE-2021-31199P1HIGHCVSS 7.8KEVvr22021-06-08
CVE-2021-31199 [HIGH] CVE-2021-31199: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
nvd
CVE-2017-0022P2MEDIUMCVSS 6.5KEVvr22017-03-17
CVE-2017-0022 [MEDIUM] CWE-119 CVE-2017-0022: Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1;
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML
nvd
CVE-2021-31201P1HIGHCVSS 7.8KEVvr22021-06-08
CVE-2021-31201 [HIGH] CVE-2021-31201: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
nvd
CVE-2019-1214P2HIGHCVSS 7.8KEVvr22019-09-11
CVE-2019-1214 [HIGH] CWE-119 CVE-2019-1214: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
nvd
CVE-2023-36584P2MEDIUMCVSS 5.4KEVvr22023-10-10
CVE-2023-36584 [MEDIUM] CVE-2023-36584: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
nvd
CVE-2018-8589P1HIGHCVSS 7.8KEVvr2-sp1v32-bit Systems Service Pack 2+4 more2018-11-14
CVE-2018-8589 [HIGH] CVE-2018-8589: An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys,
An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys, aka "Windows Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
nvd
CVE-2023-36563P2MEDIUMCVSS 5.5KEVvr22023-10-10
CVE-2023-36563 [MEDIUM] CWE-20 CVE-2023-36563: Microsoft WordPad Information Disclosure Vulnerability
Microsoft WordPad Information Disclosure Vulnerability
nvd
CVE-2025-24991P2MEDIUMCVSS 5.5KEVvr22025-03-11
CVE-2025-24991 [MEDIUM] CWE-125 CVE-2025-24991: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
nvd
CVE-2015-1769P2MEDIUMCVSS 6.6KEVvr22015-08-15
CVE-2015-1769 [MEDIUM] CWE-264 CVE-2015-1769: Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win
Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles symlinks, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Mount Manager Elevation of
nvd
CVE-2019-0703P2MEDIUMCVSS 6.5KEVvr22019-04-09
CVE-2019-0703 [MEDIUM] CVE-2019-0703: An information disclosure vulnerability exists in the way that the Windows SMB Server handles certai
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.
nvd
CVE-2022-26809P1CRITICALCVSS 9.8ExploitedPoCRansomwarevr22022-04-15
CVE-2022-26809 [CRITICAL] CVE-2022-26809: Remote Procedure Call Runtime Remote Code Execution Vulnerability
Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-34721P1CRITICALCVSS 9.8ExploitedPoCvr22022-09-13
CVE-2022-34721 [CRITICAL] CVE-2022-34721: Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
nvd
CVE-2018-3639P1MEDIUMCVSS 5.5ExploitedPoCRansomwarevr2vsp22018-05-22
CVE-2018-3639 [MEDIUM] CWE-203 CVE-2018-3639: Systems with microprocessors utilizing speculative execution and speculative execution of memory rea
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
nvd
CVE-2009-3103P1CRITICALCVSS 10.0ExploitedPoCRansomwarevsp22009-09-08
CVE-2009-3103 [CRITICAL] CWE-399 CVE-2009-3103: Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold,
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQU
nvd
CVE-2010-2729P1CRITICALCVSS 9.3ExploitedPoCvr22010-09-15
CVE-2010-2729 [CRITICAL] CWE-20 CVE-2010-2729: The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute a
nvd
CVE-2012-0003P1HIGHCVSS 8.1ExploitedPoCvr22012-01-10
CVE-2012-0003 [HIGH] CVE-2012-0003: Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) i
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."
nvd
CVE-2015-0096P2CRITICALCVSS 9.3ExploitedPoCvr22015-03-11
CVE-2015-0096 [CRITICAL] CWE-426 CVE-2015-0096: Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, leading to DLL loading duri
nvd