cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 73 of 152
CVE-2019-0985P3HIGHCVSS 7.8vr22019-06-12
CVE-2019-0985 [HIGH] CWE-787 CVE-2019-0985: A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles A remote code execution vulnerability exists when the Microsoft Speech API (SAPI) improperly handles text-to-speech (TTS) input. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. To exploit the vulnerability, an attacker would need to convince a user to open a specially
nvd
CVE-2016-3218P3HIGHCVSS 7.8vr22016-06-16
CVE-2016-3218 [HIGH] CWE-264 CVE-2016-3218: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-322
nvd
CVE-2016-3310P3HIGHCVSS 7.8vr22016-08-09
CVE-2016-3310 [HIGH] CVE-2016-3310: The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308
nvd
CVE-2016-0174P3HIGHCVSS 7.8vr22016-05-11
CVE-2016-0174 [HIGH] CVE-2016-0174: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0171, CVE-2
nvd
CVE-2021-1726P3HIGHCVSS 8.0vr22021-02-25
CVE-2021-1726 [HIGH] CVE-2021-1726: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2022-29115P3HIGHCVSS 7.8vr2vsp22022-05-10
CVE-2022-29115 [HIGH] CVE-2022-29115: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2021-27089P3HIGHCVSS 7.8vr22021-04-13
CVE-2021-27089 [HIGH] CVE-2021-27089: Microsoft Internet Messaging API Remote Code Execution Vulnerability Microsoft Internet Messaging API Remote Code Execution Vulnerability
nvd
CVE-2022-21913P3HIGHCVSS 7.5vr22022-01-11
CVE-2022-21913 [HIGH] CVE-2022-21913: Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
nvd
CVE-2022-22027P3HIGHCVSS 7.8vr22022-07-12
CVE-2022-22027 [HIGH] CVE-2022-22027: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2016-0196P3HIGHCVSS 7.8vr22016-05-11
CVE-2016-0196 [HIGH] CVE-2016-0196: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0171, CVE-2
nvd
CVE-2022-22024P3HIGHCVSS 7.8vr22022-07-12
CVE-2022-22024 [HIGH] CVE-2022-22024: Windows Fax Service Remote Code Execution Vulnerability Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-30075P3HIGHCVSS 8.0vr2-sp12024-06-11
CVE-2024-30075 [HIGH] CWE-122 CVE-2024-30075: Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
nvd
CVE-2025-27473P3HIGHCVSS 7.5vr22025-04-08
CVE-2025-27473 [HIGH] CWE-400 CVE-2025-27473: Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny servic Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
nvd
CVE-2022-30164P3HIGHCVSS 7.8vr22022-06-15
CVE-2022-30164 [HIGH] CVE-2022-30164: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
nvd
CVE-2024-49090P3HIGHCVSS 7.8vr22024-12-12
CVE-2024-49090 [HIGH] CWE-822 CVE-2024-49090: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-49088P3HIGHCVSS 7.8vr22024-12-12
CVE-2024-49088 [HIGH] CWE-126 CVE-2024-49088: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-26173P3HIGHCVSS 7.8vr22024-03-12
CVE-2024-26173 [HIGH] CWE-20 CVE-2024-26173: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-26178P3HIGHCVSS 7.8vr22024-03-12
CVE-2024-26178 [HIGH] CWE-122 CVE-2024-26178: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2025-21180P3HIGHCVSS 7.8vr22025-03-11
CVE-2025-21180 [HIGH] CWE-122 CVE-2025-21180: Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute c Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.
nvd
CVE-2019-1028P3HIGHCVSS 7.8vr22019-06-12
CVE-2019-1028 [HIGH] CVE-2019-1028: An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited th An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. Howe
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase