VendorsMicrosoftwindows_server_2008all versions
Vulnerabilities

Microsoft Windows Server 2008 for 32-bit Systems

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4076CVEs
CVE-2023-28216
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Published 2023-04-11 · Modified
7.0EPSS 0.004
CVE-2023-29368
Windows Filtering Platform Elevation of Privilege Vulnerability
Published 2023-06-13 · Analyzed
7.0EPSS 0.004
CVE-2023-29364
Windows Authentication Elevation of Privilege Vulnerability
Published 2023-06-13 · Analyzed
7.0EPSS 0.004
CVE-2025-53718
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2025-08-12 · Analyzed
7.0EPSS 0.004
CVE-2025-53140
Windows Kernel Transaction Manager Elevation of Privilege Vulnerability
Published 2025-08-12 · Analyzed
7.0EPSS 0.004
CVE-2025-58733
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.004
CVE-2025-58736
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.004
CVE-2025-58730
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.004
CVE-2024-26242
Windows Telephony Server Elevation of Privilege Vulnerability
Published 2024-04-09 · Analyzed
7.0EPSS 0.003
CVE-2022-26807
Windows Work Folder Service Elevation of Privilege Vulnerability
Published 2022-04-15 · Modified
7.0EPSS 0.003
CVE-2025-27732
Windows Graphics Component Elevation of Privilege Vulnerability
Published 2025-04-08 · Analyzed
7.0EPSS 0.003
CVE-2025-47975
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
Published 2025-07-08 · Analyzed
7.0EPSS 0.003
CVE-2025-26665
Windows upnphost.dll Elevation of Privilege Vulnerability
Published 2025-04-08 · Analyzed
7.0EPSS 0.003
CVE-2023-23385
Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
Published 2023-03-14 · Modified
7.0EPSS 0.003
CVE-2025-53134
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2025-08-12 · Analyzed
7.0EPSS 0.003
CVE-2025-21191
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability
Published 2025-04-08 · Analyzed
7.0EPSS 0.003
CVE-2026-20869
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
Published 2026-01-13 · Analyzed
7.0EPSS 0.003
CVE-2025-55678
DirectX Graphics Kernel Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.003
CVE-2023-21542
Windows Installer Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.0EPSS 0.003
CVE-2025-49762
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2025-08-12 · Analyzed
7.0EPSS 0.003
CVE-2023-24861
Windows Graphics Component Elevation of Privilege Vulnerability
Published 2023-03-14 · Modified
7.0EPSS 0.003
CVE-2025-59196
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.003
CVE-2025-58725
Windows COM+ Event System Service Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.003
CVE-2025-62217
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Published 2025-11-11 · Analyzed
7.0EPSS 0.003
CVE-2025-49678
NTFS Elevation of Privilege Vulnerability
Published 2025-07-08 · Analyzed
7.0EPSS 0.002
CVE-2025-59205
Windows Graphics Component Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.002
CVE-2014-0315
Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse cmd.exe file in the current working directory, as demonstrated by a directory that contains a .bat or .cmd file, aka "Windows File Handling Vulnerability."
Published 2014-04-08 · Modified
6.9EPSS 0.147
CVE-2010-3959
The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted CMAP table in an OpenType font, aka "OpenType CMAP Table Vulnerability."
Published 2010-12-16 · Modified
6.9EPSS 0.144
CVE-2015-0059
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted TrueType font, aka "TrueType Font Parsing Remote Code Execution Vulnerability."
Published 2015-02-11 · Modified
6.91 PoCEPSS 0.111
CVE-2015-2369
Untrusted search path vulnerability in Windows Media Device Manager in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rtf file, aka "DLL Planting Remote Code Execution Vulnerability."
Published 2015-07-14 · Modified
6.9EPSS 0.100
CVE-2015-2368
Untrusted search path vulnerability in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Windows DLL Remote Code Execution Vulnerability."
Published 2015-07-14 · Modified
6.9EPSS 0.082
CVE-2015-0003
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
Published 2015-02-11 · Modified
6.91 PoCEPSS 0.045
CVE-2015-2511
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2517, CVE-2015-2518, and CVE-2015-2546.
Published 2015-09-09 · Modified
6.91 PoCEPSS 0.039
CVE-2015-2518
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2546.
Published 2015-09-09 · Modified
6.91 PoCEPSS 0.039
CVE-2015-2517
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2518, and CVE-2015-2546.
Published 2015-09-09 · Modified
6.91 PoCEPSS 0.039
CVE-2015-6100
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6101.
Published 2015-11-11 · Modified
6.91 PoCEPSS 0.032
CVE-2015-6101
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-6100.
Published 2015-11-11 · Modified
6.91 PoCEPSS 0.031
CVE-2013-5058
Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges via a crafted application, aka "Win32k Integer Overflow Vulnerability."
Published 2013-12-11 · Modified
6.91 PoCEPSS 0.028
CVE-2009-0080
The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability."
Published 2009-04-15 · Modified
6.91 PoCEPSS 0.024
CVE-2017-0244
The kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows locally authenticated attackers to gain privileges via a crafted application, or in Windows 7 for x64-based systems, cause denial of service, aka "Windows Kernel Elevation of Privilege Vulnerability."
Published 2017-05-12 · Modified
6.9EPSS 0.020
← Prev75 / 102Next →