VendorsMicrosoftwindows_server_2008all versions
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4076CVEs
CVE-2010-0021
Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
Published 2010-02-10 · Modified
7.1EPSS 0.134
CVE-2018-8304
A denial of service vulnerability exists in Windows Domain Name System (DNS) DNSAPI.dll when it fails to properly handle DNS responses, aka "Windows DNSAPI Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-07-11 · Modified
7.1EPSS 0.126
CVE-2019-1346
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1343, CVE-2019-1347.
Published 2019-10-10 · Modified
7.11 PoCEPSS 0.109
CVE-2017-0280
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.
Published 2017-05-12 · Modified
7.1EPSS 0.072
CVE-2019-1238
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1239.
Published 2019-10-10 · Modified
7.1EPSS 0.059
CVE-2013-3876
DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate.
Published 2013-11-16 · Modified
7.1EPSS 0.052
CVE-2022-30155
Windows Kernel Denial of Service Vulnerability
Published 2022-06-15 · Modified
7.1EPSS 0.050
CVE-2013-1291
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
Published 2013-04-09 · Modified
7.1EPSS 0.046
CVE-2019-0986
Windows User Profile Service Elevation of Privilege Vulnerability
Published 2019-06-12 · Modified
7.1EPSS 0.021
CVE-2022-38042
Active Directory Domain Services Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.1EPSS 0.014
CVE-2009-2516
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."
Published 2009-10-14 · Modified
7.1EPSS 0.013
CVE-2020-0730
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-02-11 · Modified
7.1EPSS 0.009
CVE-2019-1161
Microsoft Defender Elevation of Privilege Vulnerability
Published 2019-08-14 · Modified
7.1EPSS 0.009
CVE-2022-21997
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-02-09 · Modified
7.1EPSS 0.008
CVE-2022-22022
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.008
CVE-2022-30226
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.008
CVE-2021-28446
Windows Portmapping Information Disclosure Vulnerability
Published 2021-04-13 · Modified
7.1EPSS 0.008
CVE-2025-21419
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
Published 2025-02-11 · Analyzed
7.1EPSS 0.007
CVE-2020-1461
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-07-14 · Modified
7.1EPSS 0.007
CVE-2020-0785
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Published 2020-03-12 · Modified
7.1EPSS 0.007
CVE-2023-21750
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.1EPSS 0.007
CVE-2020-1002
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Published 2020-04-15 · Modified
7.1EPSS 0.007
CVE-2023-28222
Windows Kernel Elevation of Privilege Vulnerability
Published 2023-04-11 · Modified
7.1EPSS 0.007
CVE-2023-24904
Windows Installer Elevation of Privilege Vulnerability
Published 2023-05-09 · Modified
7.1EPSS 0.006
CVE-2022-34690
Windows Fax Service Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
7.1EPSS 0.006
CVE-2022-30225
Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
Published 2022-07-12 · Modified
7.1EPSS 0.006
CVE-2023-21760
Windows Print Spooler Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.1EPSS 0.005
CVE-2023-36876
Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability
Published 2023-08-08 · Modified
7.1EPSS 0.005
CVE-2025-59208
Windows MapUrlToZone Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.1EPSS 0.005
CVE-2025-48821
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Published 2025-07-08 · Analyzed
7.1EPSS 0.005
CVE-2023-23414
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Published 2023-03-14 · Modified
7.1EPSS 0.004
CVE-2023-23407
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
Published 2023-03-14 · Modified
7.1EPSS 0.004
CVE-2025-48819
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
Published 2025-07-08 · Analyzed
7.1EPSS 0.004
CVE-2025-26633
Microsoft Management Console Security Feature Bypass Vulnerability
Published 2025-03-11 · Analyzed
7.0KEV1 PoCEPSS 0.304
CVE-2022-26904
Windows User Profile Service Elevation of Privilege Vulnerability
Published 2022-04-15 · Analyzed
7.0KEVEPSS 0.169
CVE-2023-28218
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2023-04-11 · Modified
7.0EPSS 0.123
CVE-2017-0277
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0278, and CVE-2017-0279.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-0278
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0279.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-0279
The Microsoft Server Message Block 1.0 (SMBv1) server on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to execute remote code by the way it handles certain requests, aka "Windows SMB Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0272, CVE-2017-0277, and CVE-2017-0278.
Published 2017-05-12 · Modified
7.0EPSS 0.109
CVE-2017-11780
The Server Message Block 1.0 (SMBv1) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows a remote code execution vulnerability when it fails to properly handle certain requests, aka "Windows SMB Remote Code Execution Vulnerability".
Published 2017-10-13 · Modified
7.0EPSS 0.100
← Prev72 / 102Next →