Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 20 of 84
CVE-2024-43589P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43589 [HIGH] CWE-122 CVE-2024-43589: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43453P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43453 [HIGH] CWE-122 CVE-2024-43453: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38212P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-38212 [HIGH] CWE-122 CVE-2024-38212: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-38265P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-38265 [HIGH] CWE-20 CVE-2024-38265: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43607P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43607 [HIGH] CWE-122 CVE-2024-43607: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43608P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43608 [HIGH] CWE-122 CVE-2024-43608: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43549P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43549 [HIGH] CWE-121 CVE-2024-43549: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43564P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43564 [HIGH] CWE-122 CVE-2024-43564: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2025-21222P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-21222 [HIGH] CWE-122 CVE-2025-21222: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21221P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-21221 [HIGH] CWE-122 CVE-2025-21221: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21205P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-21205 [HIGH] CWE-122 CVE-2025-21205: Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute c
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-21417P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21417 [HIGH] CWE-122 CVE-2025-21417: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21409P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21409 [HIGH] CWE-122 CVE-2025-21409: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21339P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21339 [HIGH] CWE-122 CVE-2025-21339: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21411P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21411 [HIGH] CWE-122 CVE-2025-21411: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-21413P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21413 [HIGH] CWE-122 CVE-2025-21413: Windows Telephony Service Remote Code Execution Vulnerability
Windows Telephony Service Remote Code Execution Vulnerability
nvd
CVE-2025-48817P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-48817 [HIGH] CWE-23 CVE-2025-48817: Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code ove
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-20820P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.237172026-01-13
CVE-2026-20820 [HIGH] CWE-122 CVE-2026-20820: Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-54916P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.235292025-09-09
CVE-2025-54916 [HIGH] CWE-121 CVE-2025-54916: Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
nvd
CVE-2025-21277P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21277 [HIGH] CWE-126 CVE-2025-21277: Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
nvd