Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 79 of 152
CVE-2025-47985P3HIGHCVSS 7.8vr22025-07-08
CVE-2025-47985 [HIGH] CWE-822 CVE-2025-47985: Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate priv
Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49661P3HIGHCVSS 7.8vr22025-07-08
CVE-2025-49661 [HIGH] CWE-822 CVE-2025-49661: Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55230P3HIGHCVSS 7.8vr22025-08-21
CVE-2025-55230 [HIGH] CWE-822 CVE-2025-55230: Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to eleva
Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-25004P3HIGHCVSS 7.3vr22025-10-14
CVE-2025-25004 [HIGH] CWE-284 CVE-2025-25004: Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-49670P3MEDIUMCVSS 6.5vr22025-07-08
CVE-2025-49670 [MEDIUM] CWE-122 CVE-2025-49670: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2017-8590P3HIGHCVSS 8.8vr22017-07-11
CVE-2017-8590 [HIGH] CWE-281 CVE-2017-8590: Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows Common Log File System (CLFS) driver handles objects in memory, aka "Windows CLFS Elevation of P
nvd
CVE-2020-1212P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1212 [HIGH] CVE-2020-1212: An elevation of privilege vulnerability exists when an OLE Automation component improperly handles m
An elevation of privilege vulnerability exists when an OLE Automation component improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'OLE Automation Elevation of Privilege Vulnerability'.
nvd
CVE-2012-0157P3HIGHCVSS 8.4vr22012-03-13
CVE-2012-0157 [HIGH] CWE-20 CVE-2012-0157: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Fun
nvd
CVE-2011-1231P3HIGHCVSS 8.4vr22011-04-13
CVE-2011-1231 [HIGH] CWE-476 CVE-2011-1231: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerabili
nvd
CVE-2020-1473P3HIGHCVSS 7.8vr22020-08-17
CVE-2020-1473 [HIGH] CVE-2020-1473: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabili
nvd
CVE-2022-29105P3HIGHCVSS 7.8vr2vsp22022-05-10
CVE-2022-29105 [HIGH] CVE-2022-29105: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2021-24083P3HIGHCVSS 7.8vr22021-02-25
CVE-2021-24083 [HIGH] CWE-787 CVE-2021-24083: Windows Address Book Remote Code Execution Vulnerability
Windows Address Book Remote Code Execution Vulnerability
nvd
CVE-2021-40465P3HIGHCVSS 7.8vr2vsp22021-10-13
CVE-2021-40465 [HIGH] CVE-2021-40465: Windows Text Shaping Remote Code Execution Vulnerability
Windows Text Shaping Remote Code Execution Vulnerability
nvd
CVE-2016-3355P3HIGHCVSS 7.8vr22016-09-14
CVE-2016-3355 [HIGH] CWE-264 CVE-2016-3355: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "GDI Elevation of Privilege Vulnerability."
nvd
CVE-2021-34533P3HIGHCVSS 7.8vr22021-08-12
CVE-2021-34533 [HIGH] CVE-2021-34533: Windows Graphics Component Font Parsing Remote Code Execution Vulnerability
Windows Graphics Component Font Parsing Remote Code Execution Vulnerability
nvd
CVE-2016-7221P3HIGHCVSS 7.8vr22016-11-10
CVE-2016-7221 [HIGH] CWE-264 CVE-2016-7221: Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Window
Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles DLL loading, which allows local users to gain privileges via unspecified vectors, aka "Windows IME Elevation of Priv
nvd
CVE-2020-0965P3HIGHCVSS 7.8vr22020-04-15
CVE-2020-0965 [HIGH] CVE-2020-0965: A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handl
A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'.
nvd
CVE-2016-0176P3HIGHCVSS 7.8vr22016-05-11
CVE-2016-0176 [HIGH] CWE-264 CVE-2016-0176: dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows
dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Microsoft DirectX Graphics Kernel Subsystem Elevation of P
nvd
CVE-2021-34441P3HIGHCVSS 7.8vr22021-07-16
CVE-2021-34441 [HIGH] CVE-2021-34441: Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
nvd
CVE-2021-34500P3HIGHCVSS 7.7vr22021-07-14
CVE-2021-34500 [HIGH] CVE-2021-34500: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd