Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 34 of 84
CVE-2025-48805P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-48805 [HIGH] CWE-122 CVE-2025-48805: Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to exec
Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
nvd
CVE-2025-48806P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-48806 [HIGH] CWE-416 CVE-2025-48806: Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code loc
Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
nvd
CVE-2022-30160P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.215072022-06-15
CVE-2022-30160 [HIGH] CVE-2022-30160: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2025-59187P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-59187 [HIGH] CWE-20 CVE-2025-59187: Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges loca
Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59278P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-59278 [HIGH] CWE-1287 CVE-2025-59278: Improper validation of specified type of input in Windows Authentication Methods allows an authorize
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59275P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-59275 [HIGH] CWE-122 CVE-2025-59275: Improper validation of specified type of input in Windows Authentication Methods allows an authorize
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-22034P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-22034 [HIGH] CWE-416 CVE-2022-22034: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-35751P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.216162023-05-31
CVE-2022-35751 [HIGH] CVE-2022-35751: Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
nvd
CVE-2022-22000P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.213742022-02-09
CVE-2022-22000 [HIGH] CVE-2022-22000: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2023-21812P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21812 [HIGH] CWE-122 CVE-2023-21812: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2022-22026P3HIGHCVSS 8.8≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-22026 [HIGH] CWE-787 CVE-2022-22026: Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
nvd
CVE-2023-36425P3HIGHCVSS 8.0≥ 6.0.6003.0, < 6.0.6003.223672023-11-14
CVE-2023-36425 [HIGH] CWE-122 CVE-2023-36425: Windows Distributed File System (DFS) Remote Code Execution Vulnerability
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
nvd
CVE-2022-22037P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-22037 [HIGH] CVE-2022-22037: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2025-26641P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-26641 [HIGH] CWE-400 CVE-2025-26641: Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker
Uncontrolled resource consumption in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
nvd
CVE-2022-21983P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.214462022-04-15
CVE-2022-21983 [HIGH] CVE-2022-21983: Win32 Stream Enumeration Remote Code Execution Vulnerability
Win32 Stream Enumeration Remote Code Execution Vulnerability
nvd
CVE-2025-32714P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.233512025-06-10
CVE-2025-32714 [HIGH] CWE-284 CVE-2025-32714: Improper access control in Windows Installer allows an authorized attacker to elevate privileges loc
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-21389P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21389 [HIGH] CWE-400 CVE-2025-21389: Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an un
Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.
nvd
CVE-2022-24534P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.214462022-04-15
CVE-2022-24534 [HIGH] CVE-2022-24534: Win32 Stream Enumeration Remote Code Execution Vulnerability
Win32 Stream Enumeration Remote Code Execution Vulnerability
nvd
CVE-2025-27727P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-27727 [HIGH] CWE-59 CVE-2025-27727: Improper link resolution before file access ('link following') in Windows Installer allows an author
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-21347P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.225112024-02-13
CVE-2024-21347 [HIGH] CWE-122 CVE-2024-21347: Microsoft ODBC Driver Remote Code Execution Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
nvd