Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 2 of 84
CVE-2024-38193P1HIGHCVSS 7.8KEVPoC≥ 6.0.6003.0, < 6.0.6003.228252024-08-13
CVE-2024-38193 [HIGH] CWE-416 CVE-2024-38193: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-24521P1HIGHCVSS 7.8KEVPoCRansomware≥ 6.0.6003.0, < 6.0.6003.214462022-04-15
CVE-2022-24521 [HIGH] CWE-787 CVE-2022-24521: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-34484P1HIGHCVSS 7.8KEVPoC≥ 6.0.0, < 6.0.6003.211922021-08-12
CVE-2021-34484 [HIGH] CVE-2021-34484: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2021-36955P1HIGHCVSS 7.8KEVPoCRansomware≥ 6.0.0, < 6.0.6003.212182021-09-15
CVE-2021-36955 [HIGH] CVE-2021-36955: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-43226P1HIGHCVSS 7.8KEVPoCRansomware≥ 6.0.0, < 6.0.6003.213092021-12-15
CVE-2021-43226 [HIGH] CVE-2021-43226: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-36424P1HIGHCVSS 7.8KEVPoC≥ 6.0.6003.0, < 6.0.6003.223672023-11-14
CVE-2023-36424 [HIGH] CWE-125 CVE-2023-36424: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-24990P1HIGHCVSS 7.8KEVPoC≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-24990 [HIGH] CWE-822 CVE-2025-24990: Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update.
Fax modem hardware dependent on this specific driver will no longer work on Window
nvd
CVE-2022-26904P1HIGHCVSS 7.0KEVPoC≥ 6.0.6003.0, < 6.0.6003.214462022-04-15
CVE-2022-26904 [HIGH] CWE-362 CVE-2022-26904: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21919P1HIGHCVSS 7.0KEVPoC≥ 6.0.6003.0, < 6.0.6003.213492022-01-11
CVE-2022-21919 [HIGH] CWE-59 CVE-2022-21919: Windows User Profile Service Elevation of Privilege Vulnerability
Windows User Profile Service Elevation of Privilege Vulnerability
nvd
CVE-2020-17087P1HIGHCVSS 7.8KEVPoC≥ 6.0.0, < publication2020-11-11
CVE-2020-17087 [HIGH] CWE-131 CVE-2020-17087: Windows Kernel Local Elevation of Privilege Vulnerability
Windows Kernel Local Elevation of Privilege Vulnerability
nvd
CVE-2023-28229P1HIGHCVSS 7.0KEVPoC≥ 6.0.6003.0, < 6.0.6003.220152023-04-11
CVE-2023-28229 [HIGH] CWE-591 CVE-2023-28229: Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
nvd
CVE-2021-33742P1HIGHCVSS 8.8KEV≥ 6.0.0, < 6.0.6003.21137≥ 6.0.0, < publication2021-06-08
CVE-2021-33742 [HIGH] CWE-787 CVE-2021-33742: Windows MSHTML Platform Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2024-43572P1HIGHCVSS 7.8KEV≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43572 [HIGH] CWE-707 CVE-2024-43572: Microsoft Management Console Remote Code Execution Vulnerability
Microsoft Management Console Remote Code Execution Vulnerability
nvd
CVE-2023-36036P1HIGHCVSS 7.8KEVRansomware≥ 6.0.6003.0, < 6.0.6003.223672023-11-14
CVE-2023-36036 [HIGH] CWE-122 CVE-2023-36036: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-23376P1HIGHCVSS 7.8KEVRansomware≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-23376 [HIGH] CWE-122 CVE-2023-23376: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-41073P1HIGHCVSS 7.8KEVRansomware≥ 6.0.6003.0, < 6.0.6003.217682022-11-09
CVE-2022-41073 [HIGH] CWE-787 CVE-2022-41073: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2020-1464P2MEDIUMCVSS 5.5KEV≥ 6.0.0, < publication2020-08-17
CVE-2020-1464 [MEDIUM] CWE-347 CVE-2020-1464: A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update address
nvd
CVE-2022-22718P1HIGHCVSS 7.8KEV≥ 6.0.6003.0, < 6.0.6003.213742022-02-09
CVE-2022-22718 [HIGH] CVE-2022-22718: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2025-24983P1HIGHCVSS 7.0KEV≥ 6.0.6003.0, < 6.0.6003.231682025-03-11
CVE-2025-24983 [HIGH] CWE-416 CVE-2025-24983: Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-22047P1HIGHCVSS 7.8KEV≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-22047 [HIGH] CWE-426 CVE-2022-22047: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd