Microsoft Windows Server 2008 R2 vulnerabilities
78 known vulnerabilities affecting microsoft/windows_server_2008_r2.
Total CVEs
78
CISA KEV
7
actively exploited
Public exploits
11
Exploited in wild
10
Severity breakdown
CRITICAL1HIGH46MEDIUM30LOW1
Vulnerabilities
Page 3 of 4
CVE-2018-8342P3HIGHCVSS 7.8vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-08-15
CVE-2018-8342 [HIGH] CWE-120 CVE-2018-8342: An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS)
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it, aka "Windows NDIS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8343.
nvd
CVE-2018-8415P3HIGHCVSS 7.8vx64-based Systems Service Pack 1vx64-based Systems Service Pack 1 (Server Core installation)2018-11-14
CVE-2018-8415 [HIGH] CWE-94 CVE-2018-8415: A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code
A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008
nvd
CVE-2018-8562P3HIGHCVSS 7.8vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-11-14
CVE-2018-8562 [HIGH] CWE-404 CVE-2018-8562: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server
nvd
CVE-2018-8472P3MEDIUMCVSS 5.5vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-10-10
CVE-2018-8472 [MEDIUM] CWE-200 CVE-2018-8472: An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface
An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows S
nvd
CVE-2018-8394P3MEDIUMCVSS 6.5vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-08-15
CVE-2018-8394 [MEDIUM] CWE-200 CVE-2018-8394: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Window
nvd
CVE-2018-8304P3MEDIUMCVSS 5.9vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-07-11
CVE-2018-8304 [MEDIUM] CVE-2018-8304: A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fail
A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows
nvd
CVE-2018-8308P3MEDIUMCVSS 6.6vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-07-11
CVE-2018-8308 [MEDIUM] CWE-404 CVE-2018-8308: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Win
nvd
CVE-2018-8422P4MEDIUMCVSS 6.5vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-09-13
CVE-2018-8422 [MEDIUM] CWE-200 CVE-2018-8422: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.
nvd
CVE-2018-8333P4HIGHCVSS 7.0vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-10-10
CVE-2018-8333 [HIGH] CWE-404 CVE-2018-8333: An Elevation of Privilege vulnerability exists in Filter Manager when it improperly handles objects
An Elevation of Privilege vulnerability exists in Filter Manager when it improperly handles objects in memory, aka "Microsoft Filter Manager Elevation Of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server
nvd
CVE-2018-1008P4HIGHCVSS 7.0vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-04-12
CVE-2018-1008 [HIGH] CVE-2018-1008: An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll)
An elevation of privilege vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memory, aka "OpenType Font Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windo
nvd
CVE-2018-1040P4MEDIUMCVSS 5.3vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-06-14
CVE-2018-1040 [MEDIUM] CVE-2018-1040: A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs
A denial of service vulnerability exists in the way that the Windows Code Integrity Module performs hashing, aka "Windows Code Integrity Module Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows
nvd
CVE-2018-8224P4HIGHCVSS 7.0vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-06-14
CVE-2018-8224 [HIGH] CWE-404 CVE-2018-8224: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle obje
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
nvd
CVE-2018-8169P4HIGHCVSS 7.0vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-06-14
CVE-2018-8169 [HIGH] CWE-404 CVE-2018-8169: An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library
An elevation of privilege vulnerability exists when the (Human Interface Device) HID Parser Library driver improperly handles objects in memory, aka "HIDParser Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2018-8339P4HIGHCVSS 7.0vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-08-15
CVE-2018-8339 [HIGH] CWE-20 CVE-2018-8339: An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer f
An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior, aka "Windows Installer Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows
nvd
CVE-2018-8399P4HIGHCVSS 7.0vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-08-15
CVE-2018-8399 [HIGH] CWE-404 CVE-2018-8399: An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properl
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8404.
nvd
CVE-2018-1036P4HIGHCVSS 7.0vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-06-14
CVE-2018-1036 [HIGH] CWE-732 CVE-2018-1036: An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevati
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
nvd
CVE-2018-0976P4MEDIUMCVSS 5.3vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-04-12
CVE-2018-0976 [MEDIUM] CVE-2018-0976: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.
nvd
CVE-2018-8167P4HIGHCVSS 7.0vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-05-09
CVE-2018-8167 [HIGH] CWE-404 CVE-2018-8167: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server
nvd
CVE-2018-8434P4MEDIUMCVSS 5.4vx64-based Systems Service Pack 1vx64-based Systems Service Pack 1 (Server Core installation)2018-09-13
CVE-2018-8434 [MEDIUM] CWE-20 CVE-2018-8434: An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Windows Hyper-V Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Wind
nvd
CVE-2018-8565P4MEDIUMCVSS 5.5vItanium-Based Systems Service Pack 1vx64-based Systems Service Pack 1+1 more2018-11-14
CVE-2018-8565 [MEDIUM] CWE-200 CVE-2018-8565: An information disclosure vulnerability exists when the win32k component improperly provides kernel
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka "Win32k Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Ser
nvd