📦

windows_server_2008

Vendor: microsoft

Actively Exploited 141 CISA KEV List
PoC / Exploits 454 Code Available
Total RCEs 810 Remote Access
Total CVEs 16698 Total Indexed
Avg. EPSS 8.39% Exploit Prob.
Latest CVE CVE-2026-20940 Jan 13

Security Vulnerability Index

Page 3 / 1670
7.8 CVSS

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

EPSS: 0.30%
4.6 CVSS

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

EPSS: 0.62%
6.2 CVSS

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

EPSS: 0.69%
7.8 CVSS
CVE-2026-20820
Exploit Found

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

EPSS: 2.52%
7.8 CVSS

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

EPSS: 2.39%
7.5 CVSS

Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.

EPSS: 0.52%
8.8 CVSS

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

EPSS: 1.00%
7.8 CVSS

Improper input validation in Windows Installer allows an authorized attacker to elevate privileges locally.

EPSS: 0.36%
8.8 CVSS

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

EPSS: 1.20%
7.8 CVSS

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

EPSS: 0.36%