{"schema_version":1,"title":"Microsoft Windows Server 2008 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 116 vulnerabilities in Microsoft Windows Server 2008: 0 in the last 7 days and 0 in the last 90 days, 112 of them critical and 112 exploited in the wild. The most recent, CVE-2008-0015, was published on 17 February 2026.","url":"https://junglewise.ai/threats/technologies/windows-server-2008","json_url":"https://junglewise.ai/threats/technologies/windows-server-2008.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/windows-server-2008","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":116,"critical":112,"exploited":112,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":5},"latest":[{"cve":"CVE-2008-0015","cvss":9.3,"epss":0.8159,"slug":"cve-2008-0015-microsoft-windows-video-activex-control-stack-buffer-overflow-in","title":"Microsoft Windows Video ActiveX Control stack buffer overflow in DirectShow","severity":"critical","exploited":true,"published_at":"2026-02-17T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2008-0015-microsoft-windows-video-activex-control-stack-buffer-overflow-in"},{"cve":"CVE-2026-20940","cvss":7.8,"epss":0.0045,"slug":"cve-2026-20940-microsoft-windows-cloud-files-mini-filter-driver-privilege","title":"Microsoft Windows Cloud Files Mini Filter Driver privilege escalation","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:21.313+00:00","url":"https://junglewise.ai/threats/cve-2026-20940-microsoft-windows-cloud-files-mini-filter-driver-privilege"},{"cve":"CVE-2026-20929","cvss":7.5,"epss":0.0114,"slug":"cve-2026-20929-microsoft-windows-http-sys-privilege-escalation","title":"Microsoft Windows HTTP.sys privilege escalation","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:19.827+00:00","url":"https://junglewise.ai/threats/cve-2026-20929-microsoft-windows-http-sys-privilege-escalation"},{"cve":"CVE-2026-20921","cvss":7.5,"epss":0.0008,"slug":"cve-2026-20921-microsoft-windows-smb-server-privilege-escalation-via-race","title":"Microsoft Windows SMB Server privilege escalation via race condition","severity":"high","exploited":false,"published_at":"2026-01-13T18:16:18.463+00:00","url":"https://junglewise.ai/threats/cve-2026-20921-microsoft-windows-smb-server-privilege-escalation-via-race"},{"cve":"CVE-2011-3402","cvss":8.8,"epss":0.8831,"slug":"cve-2011-3402-microsoft-windows-remote-code-execution-in-truetype-font-parsing","title":"Microsoft Windows remote code execution in TrueType font parsing engine","severity":"critical","exploited":true,"published_at":"2025-10-06T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2011-3402-microsoft-windows-remote-code-execution-in-truetype-font-parsing"},{"cve":"CVE-2025-24991","cvss":5.5,"slug":"cve-2025-24991-microsoft-windows-ntfs-out-of-bounds-read-vulnerability","title":"Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability","severity":"critical","exploited":true,"published_at":"2025-03-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-24991-microsoft-windows-ntfs-out-of-bounds-read-vulnerability"},{"cve":"CVE-2025-26633","cvss":7,"slug":"cve-2025-26633-microsoft-windows-management-console-mmc-improper-neutralization","title":"Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability","severity":"critical","exploited":true,"published_at":"2025-03-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-26633-microsoft-windows-management-console-mmc-improper-neutralization"},{"cve":"CVE-2025-24983","cvss":7,"slug":"cve-2025-24983-microsoft-windows-win32k-use-after-free-vulnerability","title":"Microsoft Windows Win32k Use-After-Free Vulnerability","severity":"critical","exploited":true,"published_at":"2025-03-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2025-24983-microsoft-windows-win32k-use-after-free-vulnerability"},{"cve":"CVE-2018-8639","cvss":7.8,"slug":"cve-2018-8639-microsoft-windows-win32k-improper-resource-shutdown-or-release","title":"Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability","severity":"critical","exploited":true,"published_at":"2025-03-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2018-8639-microsoft-windows-win32k-improper-resource-shutdown-or-release"},{"cve":"CVE-2024-35250","cvss":7.8,"slug":"cve-2024-35250-microsoft-windows-kernel-mode-driver-untrusted-pointer","title":"Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability","severity":"critical","exploited":true,"published_at":"2024-12-16T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-35250-microsoft-windows-kernel-mode-driver-untrusted-pointer"},{"cve":"CVE-2024-49138","cvss":7.8,"slug":"cve-2024-49138-microsoft-windows-common-log-file-system-clfs-driver-heap-based","title":"Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2024-12-10T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-49138-microsoft-windows-common-log-file-system-clfs-driver-heap-based"},{"cve":"CVE-2024-43451","cvss":6.5,"slug":"cve-2024-43451-microsoft-windows-ntlmv2-hash-disclosure-spoofing-vulnerability","title":"Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability","severity":"critical","exploited":true,"published_at":"2024-11-12T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-43451-microsoft-windows-ntlmv2-hash-disclosure-spoofing-vulnerability"},{"cve":"CVE-2024-43461","cvss":8.8,"slug":"cve-2024-43461-microsoft-windows-mshtml-platform-spoofing-vulnerability","title":"Microsoft Windows MSHTML Platform Spoofing Vulnerability","severity":"critical","exploited":true,"published_at":"2024-09-16T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-43461-microsoft-windows-mshtml-platform-spoofing-vulnerability"},{"cve":"CVE-2024-43455","cvss":8.8,"slug":"cve-2024-43455-microsoft-windows-remote-desktop-licensing-service-spoofing","title":"Microsoft Windows Remote Desktop Licensing Service spoofing vulnerability","severity":"high","exploited":false,"published_at":"2024-09-10T17:15:32.807+00:00","url":"https://junglewise.ai/threats/cve-2024-43455-microsoft-windows-remote-desktop-licensing-service-spoofing"},{"cve":"CVE-2024-38014","cvss":7.8,"slug":"cve-2024-38014-microsoft-windows-installer-improper-privilege-management","title":"Microsoft Windows Installer Improper Privilege Management Vulnerability","severity":"critical","exploited":true,"published_at":"2024-09-10T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38014-microsoft-windows-installer-improper-privilege-management"},{"cve":"CVE-2024-38193","cvss":7.8,"slug":"cve-2024-38193-microsoft-windows-ancillary-function-driver-for-winsock-privilege","title":"Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-38193-microsoft-windows-ancillary-function-driver-for-winsock-privilege"},{"cve":"CVE-2018-0824","cvss":8.8,"slug":"cve-2018-0824-microsoft-com-for-windows-deserialization-of-untrusted-data","title":"Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2018-0824-microsoft-com-for-windows-deserialization-of-untrusted-data"},{"cve":"CVE-2024-26169","cvss":7.8,"slug":"cve-2024-26169-microsoft-windows-error-reporting-service-improper-privilege","title":"Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability","severity":"critical","exploited":true,"published_at":"2024-06-13T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-26169-microsoft-windows-error-reporting-service-improper-privilege"},{"cve":"CVE-2023-36025","cvss":8.8,"slug":"cve-2023-36025-microsoft-windows-smartscreen-security-feature-bypass","title":"Microsoft Windows SmartScreen Security Feature Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2023-11-14T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36025-microsoft-windows-smartscreen-security-feature-bypass"},{"cve":"CVE-2023-36036","cvss":7.8,"slug":"cve-2023-36036-microsoft-windows-cloud-files-mini-filter-driver-privilege","title":"Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-11-14T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36036-microsoft-windows-cloud-files-mini-filter-driver-privilege"},{"cve":"CVE-2023-28229","cvss":7,"slug":"cve-2023-28229-microsoft-windows-cng-key-isolation-service-privilege-escalation","title":"Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-10-04T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-28229-microsoft-windows-cng-key-isolation-service-privilege-escalation"},{"cve":"CVE-2023-32046","cvss":7.8,"slug":"cve-2023-32046-microsoft-windows-mshtml-platform-privilege-escalation","title":"Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-07-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-32046-microsoft-windows-mshtml-platform-privilege-escalation"},{"cve":"CVE-2023-36874","cvss":7.8,"slug":"cve-2023-36874-microsoft-windows-error-reporting-service-privilege-escalation","title":"Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-07-11T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36874-microsoft-windows-error-reporting-service-privilege-escalation"},{"cve":"CVE-2016-0165","cvss":7.8,"slug":"cve-2016-0165-microsoft-win32k-privilege-escalation-vulnerability","title":"Microsoft Win32k Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-06-22T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2016-0165-microsoft-win32k-privilege-escalation-vulnerability"},{"cve":"CVE-2023-29336","cvss":7.8,"slug":"cve-2023-29336-microsoft-win32k-privilege-escalation-vulnerability","title":"Microsoft Win32K Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2023-05-09T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-29336-microsoft-win32k-privilege-escalation-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Microsoft Windows","slug":"windows-","vulnerabilities":963,"url":"https://junglewise.ai/threats/technologies/windows-"},{"name":"Microsoft Windows 10","slug":"windows-10","vulnerabilities":588,"url":"https://junglewise.ai/threats/technologies/windows-10"},{"name":"Microsoft Windows 11","slug":"windows-11","vulnerabilities":493,"url":"https://junglewise.ai/threats/technologies/windows-11"},{"name":"Microsoft Windows Server 2012","slug":"windows-server-2012","vulnerabilities":293,"url":"https://junglewise.ai/threats/technologies/windows-server-2012"},{"name":"Microsoft Windows Server 2016","slug":"windows-server-2016","vulnerabilities":213,"url":"https://junglewise.ai/threats/technologies/windows-server-2016"},{"name":"Microsoft Windows Server 2019","slug":"windows-server-2019","vulnerabilities":211,"url":"https://junglewise.ai/threats/technologies/windows-server-2019"},{"name":"Microsoft Windows 11 24h2","slug":"windows-11-24h2","vulnerabilities":192,"url":"https://junglewise.ai/threats/technologies/windows-11-24h2"},{"name":"Microsoft Windows Server 2022","slug":"windows-server-2022","vulnerabilities":178,"url":"https://junglewise.ai/threats/technologies/windows-server-2022"},{"name":"Microsoft Edge","slug":"edge-chromium-based","vulnerabilities":167,"url":"https://junglewise.ai/threats/technologies/edge-chromium-based"},{"name":"Microsoft Windows 11 25h2","slug":"windows-11-25h2","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/windows-11-25h2"},{"name":"Microsoft Windows 11 Version 26H1","slug":"windows-11-version-26h1","vulnerabilities":135,"url":"https://junglewise.ai/threats/technologies/windows-11-version-26h1"},{"name":"Microsoft Windows Server 2025","slug":"windows-server-2025","vulnerabilities":124,"url":"https://junglewise.ai/threats/technologies/windows-server-2025"}],"technology":{"hub":true,"name":"Microsoft Windows Server 2008","slug":"windows-server-2008","vendor":{"name":"Microsoft","slug":"microsoft","url":"https://junglewise.ai/threats/vendors/microsoft"},"aliases":[],"category":"operating-system","homepage":"https://www.microsoft.com/windowsserver","description":"A server operating system released by Microsoft as part of the Windows NT family.","url":"https://junglewise.ai/threats/technologies/windows-server-2008"},"most_severe":[{"cve":"CVE-2020-1350","cvss":10,"slug":"cve-2020-1350-microsoft-windows-dns-server-remote-code-execution-vulnerability","title":"Microsoft Windows DNS Server Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2021-11-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2020-1350-microsoft-windows-dns-server-remote-code-execution-vulnerability"},{"cve":"CVE-2017-8543","cvss":9.8,"slug":"cve-2017-8543-microsoft-windows-search-remote-code-execution-vulnerability","title":"Microsoft Windows Search Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-24T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2017-8543-microsoft-windows-search-remote-code-execution-vulnerability"},{"cve":"CVE-2008-0015","cvss":9.3,"epss":0.8159,"slug":"cve-2008-0015-microsoft-windows-video-activex-control-stack-buffer-overflow-in","title":"Microsoft Windows Video ActiveX Control stack buffer overflow in DirectShow","severity":"critical","exploited":true,"published_at":"2026-02-17T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2008-0015-microsoft-windows-video-activex-control-stack-buffer-overflow-in"},{"cve":"CVE-2014-4114","cvss":9.3,"slug":"cve-2014-4114-microsoft-windows-object-linking-embedding-ole-remote-code","title":"Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-03T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2014-4114-microsoft-windows-object-linking-embedding-ole-remote-code"},{"cve":"CVE-2011-3402","cvss":8.8,"epss":0.8831,"slug":"cve-2011-3402-microsoft-windows-remote-code-execution-in-truetype-font-parsing","title":"Microsoft Windows remote code execution in TrueType font parsing engine","severity":"critical","exploited":true,"published_at":"2025-10-06T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2011-3402-microsoft-windows-remote-code-execution-in-truetype-font-parsing"},{"cve":"CVE-2024-43461","cvss":8.8,"slug":"cve-2024-43461-microsoft-windows-mshtml-platform-spoofing-vulnerability","title":"Microsoft Windows MSHTML Platform Spoofing Vulnerability","severity":"critical","exploited":true,"published_at":"2024-09-16T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-43461-microsoft-windows-mshtml-platform-spoofing-vulnerability"},{"cve":"CVE-2018-0824","cvss":8.8,"slug":"cve-2018-0824-microsoft-com-for-windows-deserialization-of-untrusted-data","title":"Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability","severity":"critical","exploited":true,"published_at":"2024-08-05T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2018-0824-microsoft-com-for-windows-deserialization-of-untrusted-data"},{"cve":"CVE-2023-36025","cvss":8.8,"slug":"cve-2023-36025-microsoft-windows-smartscreen-security-feature-bypass","title":"Microsoft Windows SmartScreen Security Feature Bypass Vulnerability","severity":"critical","exploited":true,"published_at":"2023-11-14T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36025-microsoft-windows-smartscreen-security-feature-bypass"},{"cve":"CVE-2015-2360","cvss":8.8,"slug":"cve-2015-2360-microsoft-win32k-privilege-escalation-vulnerability","title":"Microsoft Win32k Privilege Escalation Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2015-2360-microsoft-win32k-privilege-escalation-vulnerability"},{"cve":"CVE-2014-4148","cvss":8.8,"slug":"cve-2014-4148-microsoft-windows-remote-code-execution-vulnerability","title":"Microsoft Windows Remote Code Execution Vulnerability","severity":"critical","exploited":true,"published_at":"2022-05-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2014-4148-microsoft-windows-remote-code-execution-vulnerability"}],"generated_at":"2026-09-26T09:24:00.138874+00:00"}