Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 37 of 84
CVE-2025-47976P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-47976 [HIGH] CWE-416 CVE-2025-47976: Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-55701P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-55701 [HIGH] CWE-1287 CVE-2025-55701: Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to
Improper validation of specified type of input in Microsoft Windows allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-26248P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.226182024-04-09
CVE-2024-26248 [HIGH] CWE-303 CVE-2024-26248: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2023-28254P3HIGHCVSS 7.2≥ 6.0.6003.0, < 6.0.6003.220152023-04-11
CVE-2023-28254 [HIGH] CWE-122 CVE-2023-28254: Windows DNS Server Remote Code Execution Vulnerability
Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2023-24932MEDIUMCVSS 6.7Exploited≥ 6.0.6003.0, < 6.0.6003.234182023-05-09
CVE-2023-24932 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
Secure Boot Security Feature Bypass Vulnerability
cvelistv5
CVE-2019-0906P3HIGHCVSS 7.8≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-0906 [HIGH] CWE-129 CVE-2019-0906: A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vul
nvd
CVE-2019-1009P3MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1009 [MEDIUM] CWE-200 CVE-2019-1009: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2020-1562P3HIGHCVSS 7.8≥ 6.0.0, < publication2020-08-17
CVE-2020-1562 [HIGH] CVE-2020-1562: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.
To exploit the vulnerability, a user would have to open a specially crafted file.
The security update addresses the vulnerability by correct
nvd
CVE-2021-26415P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-04-13
CVE-2021-26415 [HIGH] CWE-20 CVE-2021-26415: Windows Installer Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2022-29115P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.214812022-05-10
CVE-2022-29115 [HIGH] CVE-2022-29115: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2021-27089P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-04-13
CVE-2021-27089 [HIGH] CVE-2021-27089: Microsoft Internet Messaging API Remote Code Execution Vulnerability
Microsoft Internet Messaging API Remote Code Execution Vulnerability
nvd
CVE-2022-21913P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.213492022-01-11
CVE-2022-21913 [HIGH] CVE-2022-21913: Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
Local Security Authority (Domain Policy) Remote Protocol Security Feature Bypass
nvd
CVE-2022-22027P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-22027 [HIGH] CVE-2022-22027: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2022-22024P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-22024 [HIGH] CVE-2022-22024: Windows Fax Service Remote Code Execution Vulnerability
Windows Fax Service Remote Code Execution Vulnerability
nvd
CVE-2024-30075P3HIGHCVSS 8.0≥ 6.0.6003.0, < 6.0.6003.227202024-06-11
CVE-2024-30075 [HIGH] CWE-122 CVE-2024-30075: Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
nvd
CVE-2025-27473P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-27473 [HIGH] CWE-400 CVE-2025-27473: Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny servic
Uncontrolled resource consumption in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
nvd
CVE-2024-49090P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.230162024-12-12
CVE-2024-49090 [HIGH] CWE-822 CVE-2024-49090: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-49088P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.230162024-12-12
CVE-2024-49088 [HIGH] CWE-126 CVE-2024-49088: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-0790P3HIGHCVSS 7.8≥ 6.0.0, < publication2020-09-11
CVE-2020-0790 [HIGH] CVE-2020-0790: <p>A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.
This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if th
nvd
CVE-2024-26173P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.225672024-03-12
CVE-2024-26173 [HIGH] CWE-20 CVE-2024-26173: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd