VendorsMicrosoftwindows_server_2008any version
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3613CVEs
CVE-2025-21352
Internet Connection Sharing (ICS) Denial of Service Vulnerability
Published 2025-02-11 · Analyzed
6.5EPSS 0.010
CVE-2024-38048
Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability
Published 2024-07-09 · Modified
6.5EPSS 0.010
CVE-2024-38027
Windows Line Printer Daemon Service Denial of Service Vulnerability
Published 2024-07-09 · Modified
6.5EPSS 0.010
CVE-2025-58717
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
6.5EPSS 0.010
CVE-2025-55700
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
6.5EPSS 0.010
CVE-2025-49670
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
6.5EPSS 0.009
CVE-2024-38234
Windows Networking Denial of Service Vulnerability
Published 2024-09-10 · Analyzed
6.5EPSS 0.009
CVE-2025-58739
Microsoft Windows File Explorer Spoofing Vulnerability
Published 2025-10-14 · Analyzed
6.5EPSS 0.008
CVE-2025-21288
Windows COM Server Information Disclosure Vulnerability
Published 2025-01-14 · Analyzed
6.5EPSS 0.007
CVE-2025-21272
Windows COM Server Information Disclosure Vulnerability
Published 2025-01-14 · Analyzed
6.5EPSS 0.007
CVE-2024-43547
Windows Kerberos Information Disclosure Vulnerability
Published 2024-10-08 · Analyzed
6.5EPSS 0.007
CVE-2009-0234
The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
Published 2009-03-11 · Modified
6.4EPSS 0.344
CVE-2010-0812
Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."
Published 2010-04-14 · Modified
6.4EPSS 0.175
CVE-2012-1194
The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
Published 2012-02-17 · Modified
6.4EPSS 0.106
CVE-2010-1689
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
Published 2010-05-07 · Modified
6.4EPSS 0.066
CVE-2010-1690
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
Published 2010-05-07 · Modified
6.4EPSS 0.066
CVE-2022-41086
Windows Group Policy Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
6.4EPSS 0.003
CVE-2018-0967
A denial of service vulnerability exists in the way that Windows SNMP Service handles malformed SNMP traps, aka "Windows SNMP Service Denial of Service Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
Published 2018-04-12 · Modified
6.3EPSS 0.185
CVE-2010-0035
The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
Published 2010-02-10 · Modified
6.3EPSS 0.163
CVE-2017-0168
An information disclosure vulnerability exists when the Windows Hyper-V Network Switch running on a Windows 8.1, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, or Windows Server 2012 R2 host operating system fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Information Disclosure Vulnerability." This CVE ID is unique from CVE-2017-0169.
Published 2017-04-12 · Modified
6.3EPSS 0.056
CVE-2018-0885
The Microsoft Hyper-V Network Switch in 64-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows a denial of service vulnerability due to how input from a privileged user on a guest operating system is validated, aka "Hyper-V Denial of Service Vulnerability".
Published 2018-03-14 · Modified
6.3EPSS 0.053
CVE-2017-0182
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0183, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
Published 2017-04-12 · Modified
6.3EPSS 0.044
CVE-2017-0183
A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a guest operating system, aka "Hyper-V Denial of Service Vulnerability." This CVE ID is unique from CVE-2017-0178, CVE-2017-0179, CVE-2017-0182, CVE-2017-0184, CVE-2017-0185, and CVE-2017-0186.
Published 2017-04-12 · Modified
6.3EPSS 0.044
CVE-2016-0049
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka "Windows Kerberos Security Feature Bypass."
Published 2016-02-10 · Modified
6.21 PoCEPSS 0.131
CVE-2019-0635
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-03-06 · Modified
6.2EPSS 0.024
CVE-2007-6753
Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
Published 2012-03-28 · Modified
6.2EPSS 0.018
CVE-2019-1399
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0712, CVE-2019-1309, CVE-2019-1310.
Published 2019-11-12 · Modified
6.2EPSS 0.017
CVE-2021-33765
Windows Installer Spoofing Vulnerability
Published 2021-07-14 · Modified
6.2EPSS 0.007
CVE-2026-20821
Remote Procedure Call Information Disclosure Vulnerability
Published 2026-01-13 · Analyzed
6.2EPSS 0.007
CVE-2024-38203
Windows Package Library Manager Information Disclosure Vulnerability
Published 2024-11-12 · Analyzed
6.2EPSS 0.007
CVE-2025-47980
Windows Imaging Component Information Disclosure Vulnerability
Published 2025-07-08 · Analyzed
6.2EPSS 0.006
CVE-2025-29957
Windows Deployment Services Denial of Service Vulnerability
Published 2025-05-13 · Analyzed
6.2EPSS 0.006
CVE-2023-21697
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Published 2023-02-14 · Modified
6.2EPSS 0.005
CVE-2011-0096
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
Published 2011-01-31 · Modified
6.11 PoCEPSS 0.468
CVE-2017-0055
Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability."
Published 2017-03-17 · Modified
6.1EPSS 0.164
CVE-2011-1252
Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
Published 2011-06-16 · Modified
6.1EPSS 0.140
CVE-2015-0006
The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to trigger an unintended permissive configuration by spoofing DNS and LDAP responses on a local network, aka "NLA Security Feature Bypass Vulnerability."
Published 2015-01-13 · Modified
6.1EPSS 0.116
CVE-2021-36961
Windows Installer Denial of Service Vulnerability
Published 2021-09-15 · Modified
6.1EPSS 0.011
CVE-2019-1470
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'.
Published 2019-12-10 · Modified
6.0EPSS 0.068
CVE-2019-1166
A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection, aka 'Windows NTLM Tampering Vulnerability'.
Published 2019-10-10 · Modified
5.9EPSS 0.681
← Prev74 / 91Next →