VendorsMicrosoftwindows_server_2008any version
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3613CVEs
CVE-2022-22026
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
8.8EPSS 0.010
CVE-2025-49757
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
8.8EPSS 0.010
CVE-2024-43518
Windows Telephony Server Remote Code Execution Vulnerability
Published 2024-10-08 · Analyzed
8.8EPSS 0.010
CVE-2017-8590
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows Common Log File System (CLFS) driver handles objects in memory, aka "Windows CLFS Elevation of Privilege Vulnerability".
Published 2017-07-11 · Modified
8.8EPSS 0.010
CVE-2025-48817
Remote Desktop Client Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.010
CVE-2025-49657
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.010
CVE-2020-16891
Windows Hyper-V Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
8.8EPSS 0.009
CVE-2025-50163
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
8.8EPSS 0.009
CVE-2025-54113
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-09-09 · Analyzed
8.8EPSS 0.009
CVE-2025-48824
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.009
CVE-2025-47998
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.009
CVE-2025-49676
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.008
CVE-2025-49672
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.008
CVE-2025-49663
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.008
CVE-2025-49668
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.008
CVE-2025-49669
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.008
CVE-2025-49673
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.008
CVE-2025-49753
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.008
CVE-2023-28240
Windows Network Load Balancing Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
8.8EPSS 0.008
CVE-2025-49674
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.007
CVE-2025-58718
Remote Desktop Client Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
8.8EPSS 0.006
CVE-2025-49729
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.006
CVE-2021-42283
NTFS Elevation of Privilege Vulnerability
Published 2021-11-10 · Modified
8.8EPSS 0.005
CVE-2025-47986
Universal Print Management Service Elevation of Privilege Vulnerability
Published 2025-07-08 · Analyzed
8.8EPSS 0.004
CVE-2024-0056
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Published 2024-01-09 · Modified
8.7EPSS 0.012
CVE-2025-27737
Windows Security Zone Mapping Security Feature Bypass Vulnerability
Published 2025-04-08 · Analyzed
8.6EPSS 0.008
CVE-2019-0887
A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Published 2019-07-15 · Modified
8.5EPSS 0.710
CVE-2020-0655
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Published 2020-02-11 · Modified
8.5EPSS 0.657
CVE-2022-41076
PowerShell Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
8.5EPSS 0.605
CVE-2017-11885
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow a remote code execution vulnerability due to the way the Routing and Remote Access service handles requests, aka "Windows RRAS Service Remote Code Execution Vulnerability".
Published 2017-12-12 · Modified
8.51 PoCEPSS 0.455
CVE-2011-3416
The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
Published 2011-12-30 · Modified
8.5EPSS 0.437
CVE-2019-0603
A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to execute arbitrary code with elevated permissions. The security update addresses the vulnerability by correcting how Windows Deployment Services TFTP Server handles objects in memory, aka 'Windows Deployment Services TFTP Server Remote Code Execution Vulnerability'.
Published 2019-04-08 · Modified
8.5EPSS 0.342
CVE-2010-1256
Unspecified vulnerability in Microsoft IIS 6.0, 7.0, and 7.5, when Extended Protection for Authentication is enabled, allows remote authenticated users to execute arbitrary code via unknown vectors related to "token checking" that trigger memory corruption, aka "IIS Authentication Memory Corruption Vulnerability."
Published 2010-06-08 · Modified
8.5EPSS 0.282
CVE-2009-1546
Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
Published 2009-08-12 · Modified
8.5EPSS 0.225
CVE-2008-4268
The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary code via a crafted saved-search file, aka "Windows Saved Search Vulnerability."
Published 2008-12-10 · Modified
8.5EPSS 0.207
CVE-2008-4269
The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
Published 2008-12-10 · Modified
8.5EPSS 0.205
CVE-2008-4260
Microsoft Internet Explorer 7 sometimes attempts to access a deleted object, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
Published 2008-12-10 · Modified
8.5EPSS 0.194
CVE-2008-4258
Microsoft Internet Explorer 5.01 SP4 and 6 SP1 does not properly validate parameters during calls to navigation methods, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Parameter Validation Memory Corruption Vulnerability."
Published 2008-12-10 · Modified
8.5EPSS 0.178
CVE-2009-2499
Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka "Windows Media Playback Memory Corruption Vulnerability."
Published 2009-09-08 · Modified
8.5EPSS 0.155
CVE-2019-1019
Microsoft Windows Security Feature Bypass Vulnerability
Published 2019-06-12 · Modified
8.51 PoCEPSS 0.151
← Prev26 / 91Next →