Microsoft Windows Server 2008 vulnerabilities
3,037 known vulnerabilities affecting microsoft/windows_server_2008.
Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39
Vulnerabilities
Page 83 of 152
CVE-2023-23422P3HIGHCVSS 7.8vr22023-03-14
CVE-2023-23422 [HIGH] CVE-2023-23422: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-23423P3HIGHCVSS 7.8vr22023-03-14
CVE-2023-23423 [HIGH] CVE-2023-23423: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-37990P3HIGHCVSS 7.8vr22022-10-11
CVE-2022-37990 [HIGH] CVE-2022-37990: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-26810P3HIGHCVSS 7.8vr22022-04-15
CVE-2022-26810 [HIGH] CVE-2022-26810: Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
nvd
CVE-2025-21287P3HIGHCVSS 7.8vr22025-01-14
CVE-2025-21287 [HIGH] CWE-269 CVE-2025-21287: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2023-36790P3HIGHCVSS 7.8vr22023-10-10
CVE-2023-36790 [HIGH] CWE-284 CVE-2023-36790: Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
Windows RDP Encoder Mirror Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-21755P3HIGHCVSS 7.8vr22023-01-10
CVE-2023-21755 [HIGH] CWE-416 CVE-2023-21755: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-28272P3HIGHCVSS 7.8vr22023-04-11
CVE-2023-28272 [HIGH] CWE-191 CVE-2023-28272: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-21726P3HIGHCVSS 7.8vr22023-01-10
CVE-2023-21726 [HIGH] CWE-257 CVE-2023-21726: Windows Credential Manager User Interface Elevation of Privilege Vulnerability
Windows Credential Manager User Interface Elevation of Privilege Vulnerability
nvd
CVE-2025-47973P3HIGHCVSS 7.8vr22025-07-08
CVE-2025-47973 [HIGH] CWE-126 CVE-2025-47973: Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges l
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-47971P3HIGHCVSS 7.8vr22025-07-08
CVE-2025-47971 [HIGH] CWE-126 CVE-2025-47971: Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges l
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-21754P3HIGHCVSS 7.8vr22023-01-10
CVE-2023-21754 [HIGH] CWE-190 CVE-2023-21754: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2023-35328P3HIGHCVSS 7.8vr22023-07-11
CVE-2023-35328 [HIGH] CWE-197 CVE-2023-35328: Windows Transaction Manager Elevation of Privilege Vulnerability
Windows Transaction Manager Elevation of Privilege Vulnerability
nvd
CVE-2023-29335P3HIGHCVSS 7.5vr22023-05-09
CVE-2023-29335 [HIGH] CWE-20 CVE-2023-29335: Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2025-54894P3HIGHCVSS 7.8vr22025-09-09
CVE-2025-54894 [HIGH] CWE-122 CVE-2025-54894: Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
nvd
CVE-2023-35299P3HIGHCVSS 7.8vr22023-07-11
CVE-2023-35299 [HIGH] CWE-125 CVE-2023-35299: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-30031P3HIGHCVSS 7.8vr22024-05-14
CVE-2024-30031 [HIGH] CWE-416 CVE-2024-30031: Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
nvd
CVE-2026-20816P3HIGHCVSS 7.0vr2-sp12026-01-13
CVE-2026-20816 [HIGH] CWE-367 CVE-2026-20816: Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-60719P3HIGHCVSS 7.0vr22025-11-11
CVE-2025-60719 [HIGH] CWE-822 CVE-2025-60719: Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized
Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21197P3MEDIUMCVSS 6.5vr22025-04-08
CVE-2025-21197 [MEDIUM] CWE-284 CVE-2025-21197: Improper access control in Windows NTFS allows an authorized attacker to disclose file path informat
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.
nvd