VendorsMicrosoftwindows_server_2008r2
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems r2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3562CVEs
CVE-2025-53806
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-09-09 · Analyzed
6.5EPSS 0.012
CVE-2025-54095
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-09-09 · Analyzed
6.5EPSS 0.012
CVE-2025-53796
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-09-09 · Analyzed
6.5EPSS 0.012
CVE-2025-53798
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-09-09 · Analyzed
6.5EPSS 0.012
CVE-2025-53797
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-09-09 · Analyzed
6.5EPSS 0.012
CVE-2022-26935
Windows WLAN AutoConfig Service Information Disclosure Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.011
CVE-2025-49681
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-07-08 · Analyzed
6.5EPSS 0.011
CVE-2025-49671
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-07-08 · Analyzed
6.5EPSS 0.011
CVE-2025-62473
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-12-09 · Analyzed
6.5EPSS 0.011
CVE-2025-58729
Windows Local Session Manager (LSM) Denial of Service Vulnerability
Published 2025-10-14 · Analyzed
6.5EPSS 0.011
CVE-2025-21352
Internet Connection Sharing (ICS) Denial of Service Vulnerability
Published 2025-02-11 · Analyzed
6.5EPSS 0.010
CVE-2024-38027
Windows Line Printer Daemon Service Denial of Service Vulnerability
Published 2024-07-09 · Modified
6.5EPSS 0.010
CVE-2024-38048
Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
Published 2024-07-09 · Modified
6.5EPSS 0.010
CVE-2025-58717
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
6.5EPSS 0.010
CVE-2025-55700
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
6.5EPSS 0.010
CVE-2022-29121
Windows WLAN AutoConfig Service Denial of Service Vulnerability
Published 2022-05-10 · Modified
6.5EPSS 0.010
CVE-2023-36908
Windows Hyper-V Information Disclosure Vulnerability
Published 2023-08-08 · Modified
6.5EPSS 0.010
CVE-2025-49670
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
6.5EPSS 0.009
CVE-2024-38234
Windows Networking Denial of Service Vulnerability
Published 2024-09-10 · Analyzed
6.5EPSS 0.009
CVE-2025-58739
Microsoft Windows File Explorer Spoofing Vulnerability
Published 2025-10-14 · Analyzed
6.5EPSS 0.008
CVE-2025-21288
Windows COM Server Information Disclosure Vulnerability
Published 2025-01-14 · Analyzed
6.5EPSS 0.007
CVE-2025-21272
Windows COM Server Information Disclosure Vulnerability
Published 2025-01-14 · Analyzed
6.5EPSS 0.007
CVE-2024-43547
Windows Kerberos Information Disclosure Vulnerability
Published 2024-10-08 · Analyzed
6.5EPSS 0.007
CVE-2010-1689
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
Published 2010-05-07 · Modified
6.4EPSS 0.066
CVE-2010-1690
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
Published 2010-05-07 · Modified
6.4EPSS 0.066
CVE-2011-0091
Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
Published 2011-02-10 · Modified
6.4EPSS 0.055
CVE-2022-41086
Windows Group Policy Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
6.4EPSS 0.003
CVE-2018-0967
A denial of service vulnerability exists in the way that Windows SNMP Service handles malformed SNMP traps, aka "Windows SNMP Service Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-04-12 · Modified
6.3EPSS 0.185
CVE-2017-0168
An information disclosure vulnerability exists when the Windows Hyper-V Network Switch running on a Windows 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0169.
Published 2017-04-12 · Modified
6.3EPSS 0.056
CVE-2018-0885
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows a denial of service vulnerability due to how input from a privileged user on a guest operating system is validated, aka "Hyper-V Denial of Service Vulnerability".
Published 2018-03-14 · Modified
6.3EPSS 0.053
CVE-2017-0182
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
Published 2017-04-12 · Modified
6.3EPSS 0.044
CVE-2017-0183
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
Published 2017-04-12 · Modified
6.3EPSS 0.044
CVE-2016-0049
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka "Windows Kerberos Security Feature Bypass."
Published 2016-02-10 · Modified
6.21 PoCEPSS 0.131
CVE-2019-0635
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-03-06 · Modified
6.2EPSS 0.024
CVE-2019-1399
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1310.
Published 2019-11-12 · Modified
6.2EPSS 0.017
CVE-2021-26413
Windows Installer Spoofing Vulnerability
Published 2021-04-13 · Modified
6.2EPSS 0.007
CVE-2026-20821
Remote Procedure Call Information Disclosure Vulnerability
Published 2026-01-13 · Analyzed
6.2EPSS 0.007
CVE-2024-38203
Windows Package Library Manager Information Disclosure Vulnerability
Published 2024-11-12 · Analyzed
6.2EPSS 0.007
CVE-2025-47980
Windows Imaging Component Information Disclosure Vulnerability
Published 2025-07-08 · Analyzed
6.2EPSS 0.006
CVE-2025-29957
Windows Deployment Services Denial of Service Vulnerability
Published 2025-05-13 · Analyzed
6.2EPSS 0.006
← Prev73 / 90Next →