Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 18 of 84
CVE-2025-21303P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21303 [HIGH] CWE-122 CVE-2025-21303: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21302P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21302 [HIGH] CWE-122 CVE-2025-21302: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21305P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21305 [HIGH] CWE-122 CVE-2025-21305: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21252P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21252 [HIGH] CWE-122 CVE-2025-21252: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21306P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21306 [HIGH] CWE-122 CVE-2025-21306: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2023-21684P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21684 [HIGH] CWE-191 CVE-2023-21684: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2025-21286P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21286 [HIGH] CWE-122 CVE-2025-21286: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21266P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21266 [HIGH] CWE-122 CVE-2025-21266: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21273P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21273 [HIGH] CWE-122 CVE-2025-21273: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21282P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21282 [HIGH] CWE-122 CVE-2025-21282: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-27481P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-27481 [HIGH] CWE-121 CVE-2025-27481: Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-26663P3HIGHCVSS 8.1≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-26663 [HIGH] CWE-416 CVE-2025-26663: Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attack
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21294P3HIGHCVSS 8.1≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21294 [HIGH] CWE-591 CVE-2025-21294: Microsoft Digest Authentication Remote Code Execution Vulnerability
Microsoft Digest Authentication Remote Code Execution Vulnerability
nvd
CVE-2025-21204P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-21204 [HIGH] CWE-59 CVE-2025-21204: Improper link resolution before file access ('link following') in Windows Update Stack allows an aut
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-43455P3CRITICALCVSS 9.8≥ 6.0.6003.0, < 6.0.6003.228702024-09-10
CVE-2024-43455 [CRITICAL] CWE-20 CVE-2024-43455: Windows Remote Desktop Licensing Service Spoofing Vulnerability
Windows Remote Desktop Licensing Service Spoofing Vulnerability
nvd
CVE-2020-1285P3HIGHCVSS 8.8≥ 6.0.0, < publication2020-09-11
CVE-2020-1285 [HIGH] CVE-2020-1285: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users who
nvd
CVE-2022-24541P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.214462022-04-15
CVE-2022-24541 [HIGH] CVE-2022-24541: Windows Server Service Remote Code Execution Vulnerability
Windows Server Service Remote Code Execution Vulnerability
nvd
CVE-2022-30153P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.215072022-06-15
CVE-2022-30153 [HIGH] CVE-2022-30153: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-30161P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.215072022-06-15
CVE-2022-30161 [HIGH] CVE-2022-30161: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-29139P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.214812022-05-10
CVE-2022-29139 [HIGH] CVE-2022-29139: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd