cbcvebase.

Microsoft Windows Server 2008 Service Pack 2 vulnerabilities

1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.

Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3

Vulnerabilities

Page 11 of 84
CVE-2021-36958P3HIGHCVSS 7.8≥ 6.0.0, < 6.0.6003.212182021-08-12
CVE-2021-36958 [HIGH] CVE-2021-36958: <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly pe A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
nvd
CVE-2024-30078P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.227202024-06-11
CVE-2024-30078 [HIGH] CWE-20 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution Vulnerability Windows Wi-Fi Driver Remote Code Execution Vulnerability
nvd
CVE-2025-26645P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.231682025-03-11
CVE-2025-26645 [HIGH] CWE-23 CVE-2025-26645: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-20678P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.226182024-04-09
CVE-2024-20678 [HIGH] CWE-843 CVE-2024-20678: Remote Procedure Call Runtime Remote Code Execution Vulnerability Remote Procedure Call Runtime Remote Code Execution Vulnerability
nvd
CVE-2022-29137P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.214812022-05-10
CVE-2022-29137 [HIGH] CVE-2022-29137: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22014P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.214812022-05-10
CVE-2022-22014 [HIGH] CVE-2022-22014: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-22013P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.214812022-05-10
CVE-2022-22013 [HIGH] CVE-2022-22013: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2023-36423P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.223672023-11-14
CVE-2023-36423 [HIGH] CWE-122 CVE-2023-36423: Microsoft Remote Registry Service Remote Code Execution Vulnerability Microsoft Remote Registry Service Remote Code Execution Vulnerability
nvd
CVE-2026-20840P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.237172026-01-13
CVE-2026-20840 [HIGH] CWE-122 CVE-2026-20840: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2025-59295P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-59295 [HIGH] CWE-122 CVE-2025-59295: Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-24051P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.231682025-03-11
CVE-2025-24051 [HIGH] CWE-122 CVE-2025-24051: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-35641P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.224132023-12-12
CVE-2023-35641 [HIGH] CWE-682 CVE-2023-35641: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2025-49757P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.234182025-08-12
CVE-2025-49757 [HIGH] CWE-122 CVE-2025-49757: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-50163P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.234712025-08-12
CVE-2025-50163 [HIGH] CWE-122 CVE-2025-50163: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-54113P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.235292025-09-09
CVE-2025-54113 [HIGH] CWE-122 CVE-2025-54113: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-31962P3CRITICALCVSS 9.8≥ 6.0.0, < 6.0.6003.211372021-06-08
CVE-2021-31962 [CRITICAL] CVE-2021-31962: Kerberos AppContainer Security Feature Bypass Vulnerability Kerberos AppContainer Security Feature Bypass Vulnerability
nvd
CVE-2023-35630P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.224132023-12-12
CVE-2023-35630 [HIGH] CWE-122 CVE-2023-35630: Internet Connection Sharing (ICS) Remote Code Execution Vulnerability Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
nvd
CVE-2024-26230P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.226182024-04-09
CVE-2024-26230 [HIGH] CWE-416 CVE-2024-26230: Windows Telephony Server Elevation of Privilege Vulnerability Windows Telephony Server Elevation of Privilege Vulnerability
nvd
CVE-2025-21285P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21285 [HIGH] CWE-476 CVE-2025-21285: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd
CVE-2021-28445P3HIGHCVSS 8.8≥ 6.0.0, < publication2021-04-13
CVE-2021-28445 [HIGH] CVE-2021-28445: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
Microsoft Windows Server 2008 Service Pack 2 vulnerabilities | cvebase