VendorsMicrosoftwindows_server_2008r2
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems r2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3562CVEs
CVE-2021-28446
Windows Portmapping Information Disclosure Vulnerability
Published 2021-04-13 · Modified
7.1EPSS 0.008
CVE-2025-21419
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
Published 2025-02-11 · Analyzed
7.1EPSS 0.007
CVE-2020-1461
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
7.1EPSS 0.007
CVE-2020-0785
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.1EPSS 0.007
CVE-2023-21750
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.1EPSS 0.007
CVE-2020-1002
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-04-15 · Modified
7.1EPSS 0.007
CVE-2023-28222
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-04-11 · Modified
7.1EPSS 0.007
CVE-2023-24904
Windows Installer Elevation of Privilege Vulnerability
Published 2023-05-09 · Modified
7.1EPSS 0.006
CVE-2022-34690
Windows Fax Service Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.1EPSS 0.006
CVE-2022-30225
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.006
CVE-2023-21760
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.1EPSS 0.005
CVE-2023-36876
Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
7.1EPSS 0.005
CVE-2025-59208
Windows MapUrlToZone Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.1EPSS 0.005
CVE-2025-48821
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Published 2025-07-08 · Analyzed
7.1EPSS 0.005
CVE-2023-23414
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Published 2023-03-14 · Modified
7.1EPSS 0.004
CVE-2023-23407
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Published 2023-03-14 · Modified
7.1EPSS 0.004
CVE-2025-48819
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Published 2025-07-08 · Analyzed
7.1EPSS 0.004
CVE-2025-26633
Microsoft Management Console Security Feature Bypass Vulnerability
Published 2025-03-11 · Analyzed
7.0KEV1 PoCEPSS 0.304
CVE-2022-26904
Windows User Profile Service Elevation of Privilege Vulnerability
Published 2022-04-15 · Analyzed
7.0KEVEPSS 0.169
CVE-2023-28218
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2023-04-11 · Modified
7.0EPSS 0.123
CVE-2017-0277
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0278, and CVE-2017-0279.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-0278
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0279.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-0279
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0278.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-11780
The Server Message Block 1.0 (SMBv1) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a remote code execution vulnerability when it fails to properly handle certain requests, aka "Windows SMB Remote Code Execution Vulnerability".
Published 2017-10-13 · Modified
7.0EPSS 0.100
CVE-2024-30084
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Published 2024-06-11 · Modified
7.0EPSS 0.059
CVE-2022-34725
Windows ALPC Elevation of Privilege Vulnerability
Published 2022-09-13 · Modified
7.0EPSS 0.054
CVE-2022-30202
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.0EPSS 0.045
CVE-2017-0214
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when Windows fails to properly validate input before loading type libraries, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0213.
Published 2017-05-12 · Modified
7.01 PoCEPSS 0.035
CVE-2017-0103
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 mishandles registry objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Registry Elevation of Privilege Vulnerability."
Published 2017-03-17 · Modified
7.01 PoCEPSS 0.029
CVE-2023-36776
Win32k Elevation of Privilege Vulnerability
Published 2023-10-10 · Modified
7.0EPSS 0.024
CVE-2022-21919
Windows User Profile Service Elevation of Privilege Vulnerability
Published 2022-01-11 · Analyzed
7.0KEVEPSS 0.024
CVE-2017-0155
The Graphics component in the kernel in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Graphics Elevation of Privilege Vulnerability."
Published 2017-04-12 · Modified
7.0EPSS 0.021
CVE-2024-30090
Microsoft Streaming Service Elevation of Privilege Vulnerability
Published 2024-06-11 · Modified
7.0EPSS 0.020
CVE-2018-8333
An Elevation of Privilege vulnerability exists in Filter Manager when it improperly handles objects in memory, aka "Microsoft Filter Manager Elevation Of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-10-10 · Modified
7.0EPSS 0.019
CVE-2025-60719
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2025-11-11 · Analyzed
7.0EPSS 0.018
CVE-2023-28229
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Published 2023-04-11 · Analyzed
7.0KEVEPSS 0.017
CVE-2025-62213
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2025-11-11 · Analyzed
7.0EPSS 0.016
CVE-2017-8675
The Windows Kernel-Mode Drivers component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".. This CVE ID is unique from CVE-2017-8720.
Published 2017-09-13 · Modified
7.0EPSS 0.016
CVE-2025-24983
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Published 2025-03-11 · Analyzed
7.0KEVEPSS 0.013
CVE-2017-0246
The Graphics Component in the kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application or in Windows 7 for x64-based Systems and later, cause denial of service, aka "Win32k Elevation of Privilege Vulnerability."
Published 2017-05-12 · Modified
7.0EPSS 0.013
← Prev63 / 90Next →