📦

windows_server_2008

Vendor: microsoft

Actively Exploited 141 CISA KEV List
PoC / Exploits 454 Code Available
Total RCEs 810 Remote Access
Total CVEs 16698 Total Indexed
Avg. EPSS 8.39% Exploit Prob.
Latest CVE CVE-2026-20940 Jan 13

Security Vulnerability Index

Page 22 / 1670
6.5 CVSS

Null pointer dereference in Windows Local Security Authority (LSA) allows an authorized attacker to deny service over a network.

EPSS: 1.44%
7.5 CVSS

Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.

EPSS: 1.41%
8.8 CVSS
CVE-2025-33053
Exploit Found

External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

EPSS: 81.56%
7.5 CVSS

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

EPSS: 1.55%
7.8 CVSS

Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.

EPSS: 0.44%
7.8 CVSS

Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.

EPSS: 1.14%
7.8 CVSS

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

EPSS: 0.63%
7.8 CVSS

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

EPSS: 0.44%
8.1 CVSS
CVE-2025-32710
Exploit Found

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

EPSS: 0.95%
7.8 CVSS
CVE-2025-32709
Exploit Found

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

EPSS: 1.56%