Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 75 of 152
CVE-2023-28232P3HIGHCVSS 7.5vr22023-04-11
CVE-2023-28232 [HIGH] CWE-362 CVE-2023-28232: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2024-38198P3HIGHCVSS 7.5vr22024-08-13
CVE-2024-38198 [HIGH] CWE-345 CVE-2024-38198: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2016-3221P3HIGHCVSS 7.8vr22016-06-16
CVE-2016-3221 [HIGH] CVE-2016-3221: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3218.
nvd
CVE-2024-43456P3HIGHCVSS 7.4vr22024-10-08
CVE-2024-43456 [HIGH] CWE-284 CVE-2024-43456: Windows Remote Desktop Services Tampering Vulnerability
Windows Remote Desktop Services Tampering Vulnerability
nvd
CVE-2023-33163P3HIGHCVSS 7.5vr22023-07-11
CVE-2023-33163 [HIGH] CWE-591 CVE-2023-33163: Windows Network Load Balancing Remote Code Execution Vulnerability
Windows Network Load Balancing Remote Code Execution Vulnerability
nvd
CVE-2025-62213P3HIGHCVSS 7.0vr22025-11-11
CVE-2025-62213 [HIGH] CWE-416 CVE-2025-62213: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to ele
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54911P3HIGHCVSS 7.3vr22025-09-09
CVE-2025-54911 [HIGH] CWE-416 CVE-2025-54911: Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.
nvd
CVE-2011-2004P3HIGHCVSS 7.1vr22011-11-08
CVE-2011-2004 [HIGH] CWE-20 CVE-2011-2004: Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
nvd
CVE-2021-26435P3HIGHCVSS 7.8vr22021-09-15
CVE-2021-26435 [HIGH] CWE-787 CVE-2021-26435: Windows Scripting Engine Memory Corruption Vulnerability
Windows Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2019-0908P3HIGHCVSS 7.8vr22019-06-12
CVE-2019-0908 [HIGH] CVE-2019-0908: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-1157P3HIGHCVSS 7.8vr22019-08-14
CVE-2019-1157 [HIGH] CWE-94 CVE-2019-1157: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vuln
nvd
CVE-2019-1146P3HIGHCVSS 7.8vr22019-08-14
CVE-2019-1146 [HIGH] CVE-2019-1146: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-1156P3HIGHCVSS 7.8vr22019-08-14
CVE-2019-1156 [HIGH] CVE-2019-1156: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-1147P3HIGHCVSS 7.8vr22019-08-14
CVE-2019-1147 [HIGH] CVE-2019-1147: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-1155P3HIGHCVSS 7.8vr22019-08-14
CVE-2019-1155 [HIGH] CVE-2019-1155: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2020-1039P3HIGHCVSS 7.8vr22020-09-11
CVE-2020-1039 [HIGH] CVE-2020-1039: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2020-16924P3HIGHCVSS 7.8vr22020-10-16
CVE-2020-16924 [HIGH] CVE-2020-16924: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabi
nvd
CVE-2019-0907P3HIGHCVSS 7.8vr22019-06-12
CVE-2019-0907 [HIGH] CVE-2019-0907: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-0904P3HIGHCVSS 7.8vr22019-06-12
CVE-2019-0904 [HIGH] CVE-2019-0904: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2019-0905P3HIGHCVSS 7.8vr22019-06-12
CVE-2019-0905 [HIGH] CVE-2019-0905: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd