Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 76 of 152
CVE-2020-0645P3HIGHCVSS 7.5vr22020-03-12
CVE-2020-0645 [HIGH] CVE-2020-0645: A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request head
A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'.
nvd
CVE-2016-7246P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-7246 [HIGH] CWE-264 CVE-2016-7246: The kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows
The kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2016-7215P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-7215 [HIGH] CWE-264 CVE-2016-7215: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2021-34504P3HIGHCVSS 7.8vr22021-07-14
CVE-2021-34504 [HIGH] CVE-2021-34504: Windows Address Book Remote Code Execution Vulnerability
Windows Address Book Remote Code Execution Vulnerability
nvd
CVE-2011-0671P3HIGHCVSS 8.4vr22011-04-13
CVE-2011-0671 [HIGH] CWE-399 CVE-2011-0671: Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 an
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a diffe
nvd
CVE-2022-26926P3HIGHCVSS 7.8vr2vsp22022-05-10
CVE-2022-26926 [HIGH] CWE-284 CVE-2022-26926: Windows Address Book Remote Code Execution Vulnerability
Windows Address Book Remote Code Execution Vulnerability
nvd
CVE-2022-26903P3HIGHCVSS 7.8vr22022-04-15
CVE-2022-26903 [HIGH] CVE-2022-26903: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2021-26861P3HIGHCVSS 7.8vr22021-03-11
CVE-2021-26861 [HIGH] CVE-2021-26861: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2019-1453P3HIGHCVSS 7.5vr22019-12-10
CVE-2019-1453 [HIGH] CVE-2019-1453: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
nvd
CVE-2016-3306P3HIGHCVSS 7.8vr22016-09-14
CVE-2016-3306 [HIGH] CVE-2016-3306: The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack sessions, and consequently gain privileges, via a crafted application, aka "Windows Session Object Elevation
nvd
CVE-2016-7259P3HIGHCVSS 7.8vr22016-12-20
CVE-2016-7259 [HIGH] CWE-19 CVE-2016-7259: The Graphics Component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 200
The Graphics Component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vuln
nvd
CVE-2022-30206P3HIGHCVSS 7.8vr22022-07-12
CVE-2022-30206 [HIGH] CVE-2022-30206: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-36937P3HIGHCVSS 7.8vr22021-08-12
CVE-2021-36937 [HIGH] CVE-2021-36937: Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
Windows Media MPEG-4 Video Decoder Remote Code Execution Vulnerability
nvd
CVE-2016-0096P3HIGHCVSS 7.8vr22016-03-09
CVE-2016-0096 [HIGH] CVE-2016-0096: The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-
nvd
CVE-2021-43234P3HIGHCVSS 7.8vr22021-12-15
CVE-2021-43234 [HIGH] CVE-2021-43234: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-37955P3HIGHCVSS 7.8vr22022-09-13
CVE-2022-37955 [HIGH] CVE-2022-37955: Windows Group Policy Elevation of Privilege Vulnerability
Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2022-21913P3HIGHCVSS 7.5vr22022-01-11
CVE-2022-21913 [HIGH] CVE-2022-21913: Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
nvd
CVE-2021-41331P3HIGHCVSS 7.8vr22021-10-13
CVE-2021-41331 [HIGH] CVE-2021-41331: Windows Media Audio Decoder Remote Code Execution Vulnerability
Windows Media Audio Decoder Remote Code Execution Vulnerability
nvd
CVE-2021-41340P3HIGHCVSS 7.8vr22021-10-13
CVE-2021-41340 [HIGH] CVE-2021-41340: Windows Graphics Component Remote Code Execution Vulnerability
Windows Graphics Component Remote Code Execution Vulnerability
nvd
CVE-2017-0047P3HIGHCVSS 7.8vr22017-03-17
CVE-2017-0047 [HIGH] CVE-2017-0047: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is dif
nvd