Known vulnerabilities in Windows Server 2008 R2 SP1

Vendor: Microsoft
Version: 2008 R2 SP1
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 470
Public exploits: 16
Known exploited (KEV): 25
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2008 R2 SP1 Windows Server 2008 R2 SP1 is affected by 470 vulnerabilities: 7 critical, 142 high, 93 medium, 228 low Critical High Medium Low

Vulnerabilities (470)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121368 - Incorrect Privilege Assignment
CVE-2026-20804
CWE-266 Low
No
No
2008 R2 6.1.7601.28117, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.32230 14.01.2026 SB2026011422
#VU121363 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20847
CWE-200 Medium
No
No
2008 R2 6.1.7601.28117, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 14.01.2026 SB2026011417
#VU121329 - Improper Access Control
CVE-2026-20839
CWE-284 Low
No
No
2008 R2 6.1.7601.28117, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623, 2025 10.0.26100.32230 13.01.2026 SB20260113127
#VU121230 - Exposure of sensitive information to an unauthorized actor
CVE-2026-20805
CWE-200 High
No
Exploited
2008 R2 6.1.7601.28117, 2012 R2 6.3.9600.22968, 2012 6.2.9200.25868, 2016 10.0.14393.8783, 2019 10.0.17763.8276, 2022 23H2 10.0.25398.2092, 2022 10.0.20348.4648, 2025 10.0.26100.7623 13.01.2026 SB2026011370
#VU119481 - Heap-based Buffer Overflow
CVE-2025-62454
CWE-122 Low
No
No
2008 R2 6.1.7601.28021, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120984
#VU119477 - Out-of-bounds read
CVE-2025-62462
CWE-125 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120980
#VU119476 - Out-of-bounds read
CVE-2025-62461
CWE-125 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120980
#VU119474 - Integer underflow
CVE-2025-62567
CWE-191 Medium
No
No
2008 6.0.6003.23666, 2012 R2 6.3.9600.22920, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120978
#VU119473 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-64661
CWE-362 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120977
#VU119471 - Heap-based Buffer Overflow
CVE-2025-64679
CWE-122 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 09.12.2025 SB2025120975
#VU119470 - Heap-based Buffer Overflow
CVE-2025-64680
CWE-122 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 09.12.2025 SB2025120975
#VU119469 - Missing Authentication for Critical Function
CVE-2025-59516
CWE-306 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120974
#VU119468 - Improper Access Control
CVE-2025-59517
CWE-284 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120974
#VU119467 - Improper Access Control
CVE-2025-64673
CWE-284 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120974
#VU119466 - Exposure of sensitive information to an unauthorized actor
CVE-2025-64670
CWE-200 Medium
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120973
#VU119465 - Out-of-bounds read
CVE-2025-62572
CWE-125 Low
No
No
2008 6.0.6003.23666, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120972
#VU119459 - Heap-based Buffer Overflow
CVE-2025-62458
CWE-122 Low
No
No
2008 R2 6.1.7601.28064, 2012 R2 6.3.9600.22920, 2012 6.2.9200.25815, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529 09.12.2025 SB2025120967
#VU119458 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-64658
CWE-362 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120966
#VU119457 - Use After Free
CVE-2025-62565
CWE-416 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120966
#VU119454 - Improper Access Control
CVE-2025-62570
CWE-284 Low
No
No
2008 6.0.6003.23666, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120963


Showing elements 1 - 20 out of 470