cbcvebase.

Microsoft Windows Server 2008 vulnerabilities

3,037 known vulnerabilities affecting microsoft/windows_server_2008.

Total CVEs
3,037
CISA KEV
133
actively exploited
Public exploits
363
Exploited in wild
187
Severity breakdown
CRITICAL180HIGH1977MEDIUM841LOW39

Vulnerabilities

Page 84 of 152
CVE-2014-2781P3HIGHCVSS 7.6vr22014-07-08
CVE-2014-2781 [HIGH] CWE-264 CVE-2014-2781: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different integrity levels, which allows attackers to bypass intended access restrictions by leveraging c
nvd
CVE-2017-0190P4MEDIUMCVSS 4.4vr22017-05-12
CVE-2017-0190 [MEDIUM] CWE-200 CVE-2017-0190: The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windo The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "GDI Information Disclosure Vulnerability."
nvd
CVE-2025-54099P3HIGHCVSS 7.0vr22025-09-09
CVE-2025-54099 [HIGH] CWE-121 CVE-2025-54099: Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized at Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-58725P3HIGHCVSS 7.0vr22025-10-14
CVE-2025-58725 [HIGH] CWE-122 CVE-2025-58725: Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locall Heap-based buffer overflow in Windows COM allows an authorized attacker to elevate privileges locally.
nvd
CVE-2013-1281P3HIGHCVSS 7.1vr22013-02-13
CVE-2013-1281 [HIGH] CWE-399 CVE-2013-1281: The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attacker The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
nvd
CVE-2026-20847P3MEDIUMCVSS 6.5vr2-sp12026-01-13
CVE-2026-20847 [MEDIUM] CWE-200 CVE-2026-20847: Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized att Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2020-1492P3HIGHCVSS 7.8vr22020-08-17
CVE-2020-1492 [HIGH] CWE-787 CVE-2020-1492: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1554P3HIGHCVSS 7.8vr22020-08-17
CVE-2020-1554 [HIGH] CWE-787 CVE-2020-1554: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1379P3HIGHCVSS 7.8vr22020-08-17
CVE-2020-1379 [HIGH] CWE-787 CVE-2020-1379: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincin
nvd
CVE-2020-1311P3HIGHCVSS 7.8vr22020-06-09
CVE-2020-1311 [HIGH] CVE-2020-1311: An elevation of privilege vulnerability exists when Component Object Model (COM) client uses special An elevation of privilege vulnerability exists when Component Object Model (COM) client uses special case IIDs, aka 'Component Object Model Elevation of Privilege Vulnerability'.
nvd
CVE-2011-1282P3HIGHCVSS 8.4vr22011-07-13
CVE-2011-1282 [HIGH] CWE-119 CVE-2011-1282: The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows lo
nvd
CVE-2011-1881P3HIGHCVSS 8.4vr22011-07-13
CVE-2011-1881 [HIGH] CWE-476 CVE-2011-1881: win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed
nvd
CVE-2017-0180P3HIGHCVSS 7.6vr22017-04-12
CVE-2017-0180 [HIGH] CVE-2017-0180: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host s A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0181.
nvd
CVE-2017-0163P3HIGHCVSS 7.6vr22017-04-12
CVE-2017-0163 [HIGH] CVE-2017-0163: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host s A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0180, and CVE-2017-0181.
nvd
CVE-2017-0181P3HIGHCVSS 7.6vr22017-04-12
CVE-2017-0181 [HIGH] CVE-2017-0181: A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Window A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Execution Vulnerability." This CVE ID is unique from CVE-2017-0162, CVE-2017-0163, and CVE-2017-0180.
nvd
CVE-2020-17043P3HIGHCVSS 7.8vr22020-11-11
CVE-2020-17043 [HIGH] CVE-2020-17043: Windows Remote Access Elevation of Privilege Vulnerability Windows Remote Access Elevation of Privilege Vulnerability
nvd
CVE-2022-37985P4MEDIUMCVSS 5.5vr22022-10-11
CVE-2022-37985 [MEDIUM] CVE-2022-37985: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2016-3252P3HIGHCVSS 7.3vr22016-07-13
CVE-2016-3252 [HIGH] CVE-2016-3252: The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3249, CVE-2
nvd
CVE-2021-36932P3HIGHCVSS 7.5vr22021-08-12
CVE-2021-36932 [HIGH] CVE-2021-36932: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
nvd
CVE-2016-0014P3HIGHCVSS 7.8vr22016-01-13
CVE-2016-0014 [HIGH] CWE-426 CVE-2016-0014: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Elevation of Privilege Vulnerability."
nvd
Microsoft Windows Server 2008 vulnerabilities | cvebase