cbcvebase.

Microsoft Windows Server 2008 Service Pack 2 vulnerabilities

1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.

Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3

Vulnerabilities

Page 12 of 84
CVE-2025-21371P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.231172025-02-11
CVE-2025-21371 [HIGH] CWE-122 CVE-2025-21371: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2021-33780P3HIGHCVSS 8.8≥ 6.0.0, < 6.0.6003.211672021-07-14
CVE-2021-33780 [HIGH] CVE-2021-33780: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-24088P3HIGHCVSS 8.8≥ 6.0.0, < publication2021-02-25
CVE-2021-24088 [HIGH] CVE-2021-24088: Windows Local Spooler Remote Code Execution Vulnerability Windows Local Spooler Remote Code Execution Vulnerability
nvd
CVE-2025-50177P3HIGHCVSS 8.1≥ 6.0.6003.0, < 6.0.6003.234712025-08-12
CVE-2025-50177 [HIGH] CWE-362 CVE-2025-50177: Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a net Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-28455P3HIGHCVSS 8.8≥ 6.0.0, < 6.0.6003.211172021-05-11
CVE-2021-28455 [HIGH] CVE-2021-28455: Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
nvd
CVE-2025-21407P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.231172025-02-11
CVE-2025-21407 [HIGH] CWE-122 CVE-2025-21407: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21406P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.231172025-02-11
CVE-2025-21406 [HIGH] CWE-416 CVE-2025-21406: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21190P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.231172025-02-11
CVE-2025-21190 [HIGH] CWE-122 CVE-2025-21190: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21201P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.231172025-02-11
CVE-2025-21201 [HIGH] CWE-415 CVE-2025-21201: Windows Telephony Server Remote Code Execution Vulnerability Windows Telephony Server Remote Code Execution Vulnerability
nvd
CVE-2025-21200P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.231172025-02-11
CVE-2025-21200 [HIGH] CWE-122 CVE-2025-21200: Windows Telephony Service Remote Code Execution Vulnerability Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2021-33746P3HIGHCVSS 8.8≥ 6.0.0, < 6.0.6003.211672021-07-14
CVE-2021-33746 [HIGH] CVE-2021-33746: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-35322P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.221752023-07-11
CVE-2023-35322 [HIGH] CWE-121 CVE-2023-35322: Windows Deployment Services Remote Code Execution Vulnerability Windows Deployment Services Remote Code Execution Vulnerability
nvd
CVE-2023-21695P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21695 [HIGH] CWE-122 CVE-2023-21695: Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
nvd
CVE-2025-33066P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.233512025-06-10
CVE-2025-33066 [HIGH] CWE-122 CVE-2025-33066: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49657P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-49657 [HIGH] CWE-122 CVE-2025-49657: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-48824P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-48824 [HIGH] CWE-122 CVE-2025-48824: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-47998P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-47998 [HIGH] CWE-122 CVE-2025-47998: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49676P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-49676 [HIGH] CWE-122 CVE-2025-49676: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-49672P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-49672 [HIGH] CWE-122 CVE-2025-49672: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorize Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2021-43215P3CRITICALCVSS 9.8≥ 6.0.0, < 6.0.6003.213092021-12-15
CVE-2021-43215 [CRITICAL] CWE-787 CVE-2021-43215: iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
nvd
Microsoft Windows Server 2008 Service Pack 2 vulnerabilities | cvebase