📦

windows_server_2008

Vendor: microsoft

Actively Exploited 141 CISA KEV List
PoC / Exploits 454 Code Available
Total RCEs 810 Remote Access
Total CVEs 16698 Total Indexed
Avg. EPSS 8.39% Exploit Prob.
Latest CVE CVE-2026-20940 Jan 13

Security Vulnerability Index

Page 2 / 1670
7.0 CVSS

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.

EPSS: 0.29%
8.8 CVSS

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

EPSS: 1.34%
7.8 CVSS

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

EPSS: 7.98%
7.5 CVSS

Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

EPSS: 0.97%
6.5 CVSS

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

EPSS: 1.30%
7.8 CVSS

Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

EPSS: 3.32%
7.8 CVSS

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

EPSS: 0.55%
5.5 CVSS

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

EPSS: 0.46%
4.6 CVSS

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

EPSS: 0.71%
5.5 CVSS

Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.

EPSS: 0.36%