VendorsMicrosoftwindows_server_2008r2
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems r2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3562CVEs
CVE-2022-30133
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Published 2022-08-09 · Modified
9.8EPSS 0.027
CVE-2023-36910
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.025
CVE-2023-35385
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.025
CVE-2021-1722
Windows Fax Service Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
9.8EPSS 0.024
CVE-2023-36434
Windows IIS Server Elevation of Privilege Vulnerability
Published 2023-10-10 · Modified
9.8EPSS 0.024
CVE-2024-38199
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
9.8EPSS 0.022
CVE-2023-32057
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.022
CVE-2024-38074
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
9.8EPSS 0.022
CVE-2023-32015
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-06-13 · Analyzed
9.8EPSS 0.020
CVE-2023-28250
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-04-11 · Modified
9.8EPSS 0.020
CVE-2022-35744
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Published 2023-05-31 · Modified
9.8EPSS 0.020
CVE-2023-29363
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-06-13 · Analyzed
9.8EPSS 0.019
CVE-2023-32014
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
Published 2023-06-13 · Analyzed
9.8EPSS 0.019
CVE-2025-21307
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
9.8EPSS 0.019
CVE-2023-35365
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.018
CVE-2023-36911
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.017
CVE-2023-35366
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.017
CVE-2023-35367
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.017
CVE-2024-43455
Windows Remote Desktop Licensing Service Spoofing Vulnerability
Published 2024-09-10 · Analyzed
9.8EPSS 0.017
CVE-2023-36903
Windows System Assessment Tool Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
9.8EPSS 0.016
CVE-2023-21708
Remote Procedure Call Runtime Remote Code Execution Vulnerability
Published 2023-03-14 · Modified
9.8EPSS 0.015
CVE-2023-33154
Windows Partition Management Driver Elevation of Privilege Vulnerability
Published 2023-07-11 · Modified
9.8EPSS 0.008
CVE-2017-0199
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."
Published 2017-04-12 · Analyzed
9.3KEV3 PoCEPSS 0.995
CVE-2017-0148
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.
Published 2017-03-17 · Analyzed
9.3KEV3 PoCEPSS 0.994
CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Published 2022-06-01 · Analyzed
9.3KEVEPSS 0.992
CVE-2017-0144
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Published 2017-03-17 · Analyzed
9.3KEV6 PoCEPSS 0.992
CVE-2010-3962
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
Published 2010-11-05 · Analyzed
9.3KEV3 PoCEPSS 0.968
CVE-2014-6332
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."
Published 2014-11-11 · Analyzed
9.3KEV9 PoCEPSS 0.950
CVE-2017-0143
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.
Published 2017-03-17 · Analyzed
9.3KEV4 PoCEPSS 0.933
CVE-2010-0249
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."
Published 2010-01-15 · Analyzed
9.3KEV2 PoCEPSS 0.919
CVE-2010-2568
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
Published 2010-07-22 · Analyzed
9.3KEV2 PoCEPSS 0.913
CVE-2017-8464
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows local users or remote attackers to execute arbitrary code via a crafted .LNK file, which is not properly handled during icon display in Windows Explorer or any other application that parses the icon of the shortcut. aka "LNK Remote Code Execution Vulnerability."
Published 2017-06-15 · Analyzed
9.3KEV2 PoCEPSS 0.899
CVE-2017-0146
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.
Published 2017-03-17 · Analyzed
9.3KEV4 PoCEPSS 0.899
CVE-2017-0145
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.
Published 2017-03-17 · Analyzed
9.3KEV3 PoCEPSS 0.899
CVE-2017-8759
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
Published 2017-09-13 · Analyzed
9.3KEV1 PoCEPSS 0.887
CVE-2012-0151
The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
Published 2012-04-10 · Analyzed
9.3KEVEPSS 0.877
CVE-2015-2426
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."
Published 2015-07-20 · Analyzed
9.3KEV1 PoCEPSS 0.866
CVE-2021-1675
Windows Print Spooler Remote Code Execution Vulnerability
Published 2021-06-08 · Analyzed
9.3KEVEPSS 0.853
CVE-2014-0322
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors involving crafted JavaScript code, CMarkup, and the onpropertychange attribute of a script element, as exploited in the wild in January and February 2014.
Published 2014-02-14 · Analyzed
9.3KEV2 PoCEPSS 0.851
CVE-2012-1889
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
Published 2012-06-13 · Analyzed
9.3KEV1 PoCEPSS 0.835
← Prev3 / 90Next →