📦

windows_server_2008

Vendor: microsoft

Actively Exploited 141 CISA KEV List
PoC / Exploits 454 Code Available
Total RCEs 810 Remote Access
Total CVEs 16698 Total Indexed
Avg. EPSS 8.39% Exploit Prob.
Latest CVE CVE-2026-20940 Jan 13

Security Vulnerability Index

Page 29 / 1670
8.8 CVSS

Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.

EPSS: 1.17%
7.8 CVSS
CVE-2025-21204
Exploit Found

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

EPSS: 6.39%
6.5 CVSS

Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

EPSS: 1.34%
6.5 CVSS

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.

EPSS: 2.63%
7.0 CVSS

Time-of-check time-of-use (toctou) race condition in Windows Local Security Authority (LSA) allows an authorized attacker to elevate privileges locally.

EPSS: 0.29%
7.0 CVSS
CVE-2025-26633
Exploit Found

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

EPSS: 31.89%
6.5 CVSS

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

EPSS: 1.19%
7.8 CVSS

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

EPSS: 2.09%
5.5 CVSS

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.

EPSS: 0.96%
5.5 CVSS

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

EPSS: 1.85%