Microsoft Windows Server 2008
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Windows Server 2008.
By the Year
In 2025 there have been 104 vulnerabilities in Microsoft Windows Server 2008 with an average score of 7.4 out of ten. Last year, in 2024 Windows Server 2008 had 299 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Windows Server 2008 in 2025 could surpass last years number. Last year, the average CVE base score was greater by 0.27
Year | Vulnerabilities | Average Score |
---|---|---|
2025 | 104 | 7.44 |
2024 | 299 | 7.71 |
2023 | 363 | 7.55 |
2022 | 334 | 7.56 |
2021 | 279 | 7.62 |
2020 | 382 | 7.42 |
2019 | 314 | 7.27 |
2018 | 158 | 6.48 |
It may take a day or so for new Windows Server 2008 vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Windows Server 2008 Security Vulnerabilities
Use after free in Windows Common Log File System Driver
CVE-2025-29824
7.8 - High
- April 08, 2025
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Dangling pointer
External control of file name or path in Windows NTLM
CVE-2025-24054
5.4 - Medium
- March 11, 2025
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
External Control of File Name or Path
Integer overflow or wraparound in Windows Fast FAT Driver
CVE-2025-24985
7.8 - High
- March 11, 2025
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
Integer Overflow or Wraparound
Use after free in Windows Win32 Kernel Subsystem
CVE-2025-24983
7 - High
- March 11, 2025
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
Dangling pointer
Out-of-bounds read in Windows NTFS
CVE-2025-24991
5.5 - Medium
- March 11, 2025
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds Read
Heap-based buffer overflow in Windows NTFS
CVE-2025-24993
7.8 - High
- March 11, 2025
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Heap-based Buffer Overflow
Improper neutralization in Microsoft Management Console
CVE-2025-26633
7 - High
- March 11, 2025
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Improper Neutralization
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21190
8.8 - High
- February 11, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21200
8.8 - High
- February 11, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Server Remote Code Execution Vulnerability
CVE-2025-21201
8.8 - High
- February 11, 2025
Windows Telephony Server Remote Code Execution Vulnerability
Double-free
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-21208
8.8 - High
- February 11, 2025
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows NTFS Elevation of Privilege Vulnerability
CVE-2025-21337
3.3 - Low
- February 11, 2025
Windows NTFS Elevation of Privilege Vulnerability
Authorization
Windows Kerberos Denial of Service Vulnerability
CVE-2025-21350
5.9 - Medium
- February 11, 2025
Windows Kerberos Denial of Service Vulnerability
Improper Input Validation
Microsoft Digest Authentication Remote Code Execution Vulnerability
CVE-2025-21368
8.8 - High
- February 11, 2025
Microsoft Digest Authentication Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft Digest Authentication Remote Code Execution Vulnerability
CVE-2025-21369
8.8 - High
- February 11, 2025
Microsoft Digest Authentication Remote Code Execution Vulnerability
Integer Overflow or Wraparound
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21371
8.8 - High
- February 11, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Installer Elevation of Privilege Vulnerability
CVE-2025-21373
7.8 - High
- February 11, 2025
Windows Installer Elevation of Privilege Vulnerability
insecure temporary file
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
CVE-2025-21375
7.8 - High
- February 11, 2025
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
Improper Input Validation
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2025-21376
8.1 - High
- February 11, 2025
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Race Condition
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21181
7.5 - High
- February 11, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Resource Exhaustion
NTLM Hash Disclosure Spoofing Vulnerability
CVE-2025-21377
6.5 - Medium
- February 11, 2025
NTLM Hash Disclosure Spoofing Vulnerability
External Control of File Name or Path
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21406
8.8 - High
- February 11, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Dangling pointer
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21407
8.8 - High
- February 11, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2025-21410
8.8 - High
- February 11, 2025
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
CVE-2025-21419
7.1 - High
- February 11, 2025
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
insecure temporary file
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2025-21418
7.8 - High
- February 11, 2025
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21417
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21413
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21411
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21409
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows upnphost.dll Denial of Service Vulnerability
CVE-2025-21389
7.5 - High
- January 14, 2025
Windows upnphost.dll Denial of Service Vulnerability
Resource Exhaustion
Windows Installer Elevation of Privilege Vulnerability
CVE-2025-21287
7.8 - High
- January 14, 2025
Windows Installer Elevation of Privilege Vulnerability
Improper Privilege Management
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21341
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21339
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
GDI+ Remote Code Execution Vulnerability
CVE-2025-21338
7.8 - High
- January 14, 2025
GDI+ Remote Code Execution Vulnerability
Integer Overflow or Wraparound
Windows Cryptographic Information Disclosure Vulnerability
CVE-2025-21336
5.6 - Medium
- January 14, 2025
Windows Cryptographic Information Disclosure Vulnerability
Side Channel Attack
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-21332
8.8 - High
- January 14, 2025
MapUrlToZone Security Feature Bypass Vulnerability
Improper Resolution of Path Equivalence
Windows Installer Elevation of Privilege Vulnerability
CVE-2025-21331
7.3 - High
- January 14, 2025
Windows Installer Elevation of Privilege Vulnerability
insecure temporary file
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-21328
4.3 - Medium
- January 14, 2025
MapUrlToZone Security Feature Bypass Vulnerability
Improper Resolution of Path Equivalence
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21327
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21324
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21320
5.5 - Medium
- January 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Insertion of Sensitive Information into Log File
Windows Kernel Memory Information Disclosure Vulnerability
CVE-2025-21319
5.5 - Medium
- January 14, 2025
Windows Kernel Memory Information Disclosure Vulnerability
Insertion of Sensitive Information into Log File
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-21329
4.3 - Medium
- January 14, 2025
MapUrlToZone Security Feature Bypass Vulnerability
Improper Resolution of Path Equivalence
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21310
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2025-21307
9.8 - Critical
- January 14, 2025
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Dangling pointer
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21306
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21305
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21303
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21302
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows upnphost.dll Denial of Service Vulnerability
CVE-2025-21300
7.5 - High
- January 14, 2025
Windows upnphost.dll Denial of Service Vulnerability
Resource Exhaustion
Windows OLE Remote Code Execution Vulnerability
CVE-2025-21298
9.8 - Critical
- January 14, 2025
Windows OLE Remote Code Execution Vulnerability
Dangling pointer
Windows Remote Desktop Services Remote Code Execution Vulnerability
CVE-2025-21297
8.1 - High
- January 14, 2025
Windows Remote Desktop Services Remote Code Execution Vulnerability
Dangling pointer
BranchCache Remote Code Execution Vulnerability
CVE-2025-21296
7.5 - High
- January 14, 2025
BranchCache Remote Code Execution Vulnerability
Dangling pointer
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
CVE-2025-21295
8.1 - High
- January 14, 2025
SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
Dangling pointer
Microsoft Digest Authentication Remote Code Execution Vulnerability
CVE-2025-21294
8.1 - High
- January 14, 2025
Microsoft Digest Authentication Remote Code Execution Vulnerability
Sensitive Data Storage in Improperly Locked Memory
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21290
7.5 - High
- January 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Resource Exhaustion
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21289
7.5 - High
- January 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Resource Exhaustion
Windows COM Server Information Disclosure Vulnerability
CVE-2025-21288
6.5 - Medium
- January 14, 2025
Windows COM Server Information Disclosure Vulnerability
Use of Uninitialized Resource
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21286
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21285
7.5 - High
- January 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
NULL Pointer Dereference
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21252
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21251
7.5 - High
- January 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Resource Exhaustion
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21250
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21249
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21246
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Out-of-bounds Read
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21244
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Integer Overflow or Wraparound
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-21189
4.3 - Medium
- January 14, 2025
MapUrlToZone Security Feature Bypass Vulnerability
Improper Resolution of Path Equivalence
Windows BitLocker Information Disclosure Vulnerability
CVE-2025-21210
4.2 - Medium
- January 14, 2025
Windows BitLocker Information Disclosure Vulnerability
Failing Open
Windows BitLocker Information Disclosure Vulnerability
CVE-2025-21214
4.2 - Medium
- January 14, 2025
Windows BitLocker Information Disclosure Vulnerability
Information Disclosure
Secure Boot Security Feature Bypass Vulnerability
CVE-2025-21215
4.6 - Medium
- January 14, 2025
Secure Boot Security Feature Bypass Vulnerability
Out-of-bounds Read
Windows NTLM Spoofing Vulnerability
CVE-2025-21217
6.5 - Medium
- January 14, 2025
Windows NTLM Spoofing Vulnerability
Protection Mechanism Failure
Microsoft Message Queuing Information Disclosure Vulnerability
CVE-2025-21220
7.5 - High
- January 14, 2025
Microsoft Message Queuing Information Disclosure Vulnerability
Use of Uninitialized Resource
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21223
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21226
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21227
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21228
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21230
7.5 - High
- January 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Improper Input Validation
IP Helper Denial of Service Vulnerability
CVE-2025-21231
7.5 - High
- January 14, 2025
IP Helper Denial of Service Vulnerability
Resource Exhaustion
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21255
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21256
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21258
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21260
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21261
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21263
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21265
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2025-21268
4.3 - Medium
- January 14, 2025
MapUrlToZone Security Feature Bypass Vulnerability
Improper Resolution of Path Equivalence
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21243
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Integer Overflow or Wraparound
Windows Kerberos Information Disclosure Vulnerability
CVE-2025-21242
5.9 - Medium
- January 14, 2025
Windows Kerberos Information Disclosure Vulnerability
Information Disclosure
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21266
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21240
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21238
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21237
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21236
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21245
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Out-of-bounds Read
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21233
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Windows Digital Media Elevation of Privilege Vulnerability
CVE-2025-21232
6.6 - Medium
- January 14, 2025
Windows Digital Media Elevation of Privilege Vulnerability
Out-of-bounds Read
Windows COM Server Information Disclosure Vulnerability
CVE-2025-21272
6.5 - Medium
- January 14, 2025
Windows COM Server Information Disclosure Vulnerability
Use of Uninitialized Resource
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2025-21270
7.5 - High
- January 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Resource Exhaustion
Windows Telephony Service Remote Code Execution Vulnerability
CVE-2025-21282
8.8 - High
- January 14, 2025
Windows Telephony Service Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Windows Server 2025 or by Microsoft? Click the Watch button to subscribe.
