VendorsMicrosoftwindows_server_2008all versions
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4076CVEs
CVE-2025-55335
Windows NTFS Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.4EPSS 0.003
CVE-2017-0213
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.
Published 2017-05-12 · Analyzed
7.3KEV1 PoCEPSS 0.841
CVE-2022-35793
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.3EPSS 0.091
CVE-2016-0006
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0007.
Published 2016-01-13 · Modified
7.31 PoCEPSS 0.040
CVE-2016-3252
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3249, CVE-2016-3254, and CVE-2016-3286.
Published 2016-07-13 · Modified
7.3EPSS 0.038
CVE-2016-7211
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." a different vulnerability than CVE-2016-3266, CVE-2016-3376, and CVE-2016-7185.
Published 2016-10-14 · Modified
7.3EPSS 0.030
CVE-2016-3249
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3252, CVE-2016-3254, and CVE-2016-3286.
Published 2016-07-13 · Modified
7.3EPSS 0.025
CVE-2016-3286
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3249, CVE-2016-3252, and CVE-2016-3254.
Published 2016-07-13 · Modified
7.3EPSS 0.025
CVE-2024-21409
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Published 2024-04-09 · Modified
7.3EPSS 0.025
CVE-2017-0298
A DCOM object in Helppane.exe in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016, when configured to run as the interactive user, allows an authenticated attacker to run arbitrary code in another user's session, aka "Windows COM Session Elevation of Privilege Vulnerability."
Published 2017-06-15 · Modified
7.3EPSS 0.019
CVE-2010-3957
Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Double Free Vulnerability."
Published 2010-12-16 · Modified
7.3EPSS 0.018
CVE-2024-43475
Microsoft Windows Admin Center Information Disclosure Vulnerability
Published 2024-09-10 · Analyzed
7.3EPSS 0.018
CVE-2022-30170
Windows Credential Roaming Service Elevation of Privilege Vulnerability
Published 2022-09-13 · Modified
7.3EPSS 0.016
CVE-2024-38081
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Published 2024-07-09 · Modified
7.3EPSS 0.013
CVE-2024-30093
Windows Storage Elevation of Privilege Vulnerability
Published 2024-06-11 · Modified
7.3EPSS 0.011
CVE-2025-21331
Windows Installer Elevation of Privilege Vulnerability
Published 2025-01-14 · Analyzed
7.3EPSS 0.010
CVE-2023-36583
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36578
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36590
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36582
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36570
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36571
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36572
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36573
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36574
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36575
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36589
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2023-36592
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.010
CVE-2024-26232
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2024-04-09 · Analyzed
7.3EPSS 0.009
CVE-2023-36591
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
7.3EPSS 0.009
CVE-2024-26216
Windows File Server Resource Management Service Elevation of Privilege Vulnerability
Published 2024-04-09 · Analyzed
7.3EPSS 0.009
CVE-2025-54911
Windows BitLocker Elevation of Privilege Vulnerability
Published 2025-09-09 · Analyzed
7.3EPSS 0.007
CVE-2025-50161
Win32k Elevation of Privilege Vulnerability
Published 2025-08-12 · Analyzed
7.3EPSS 0.006
CVE-2025-25004
PowerShell Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.3EPSS 0.005
CVE-2015-6132
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."
Published 2015-12-09 · Modified
7.22 PoCEPSS 0.847
CVE-2015-6128
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."
Published 2015-12-09 · Modified
7.22 PoCEPSS 0.819
CVE-2018-8120
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
Published 2018-05-09 · Analyzed
7.2KEV1 PoCEPSS 0.734
CVE-2012-0217
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1; and possibly other operating systems, when running on an Intel processor, incorrectly uses the sysret path in cases where a certain address is not a canonical address, which allows local users to gain privileges via a crafted application. NOTE: because this issue is due to incorrect use of the Intel specification, it should have been split into separate identifiers; however, there was some value in preserving the original mapping of the multi-codebase coordinated-disclosure effort to a single identifier.
Published 2012-06-12 · Modified
7.23 PoCEPSS 0.398
CVE-2015-2525
Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass intended filesystem restrictions and delete arbitrary files via unspecified vectors, aka "Windows Task File Deletion Elevation of Privilege Vulnerability."
Published 2015-09-09 · Modified
7.21 PoCEPSS 0.315
CVE-2010-3338
The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, aka "Task Scheduler Vulnerability." NOTE: this might overlap CVE-2010-3888.
Published 2010-12-16 · Modified
7.22 PoCEPSS 0.217
← Prev66 / 102Next →