cbcvebase.

Microsoft Windows Server 2008 Service Pack 2 vulnerabilities

1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.

Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3

Vulnerabilities

Page 41 of 84
CVE-2024-38249P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.228702024-09-10
CVE-2024-38249 [HIGH] CWE-416 CVE-2024-38249: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2021-1657P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-01-12
CVE-2021-1657 [HIGH] CWE-269 CVE-2021-1657: Windows Fax Compose Form Remote Code Execution Vulnerability Windows Fax Compose Form Remote Code Execution Vulnerability
nvd
CVE-2024-30094P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.227202024-06-11
CVE-2024-30094 [HIGH] CWE-122 CVE-2024-30094: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2022-24485P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.214462022-04-15
CVE-2022-24485 [HIGH] CVE-2022-24485: Win32 File Enumeration Remote Code Execution Vulnerability Win32 File Enumeration Remote Code Execution Vulnerability
nvd
CVE-2024-38261P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-38261 [HIGH] CWE-20 CVE-2024-38261: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43626P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-43626 [HIGH] CWE-122 CVE-2024-43626: Windows Telephony Service Elevation of Privilege Vulnerability Windows Telephony Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43556P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43556 [HIGH] CWE-416 CVE-2024-43556: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-30049P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.226682024-05-14
CVE-2024-30049 [HIGH] CWE-416 CVE-2024-30049: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-38079P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.227692024-07-09
CVE-2024-38079 [HIGH] CWE-122 CVE-2024-38079: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38250P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.228702024-09-10
CVE-2024-38250 [HIGH] CWE-126 CVE-2024-38250: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2025-49689P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-49689 [HIGH] CWE-125 CVE-2025-49689: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevat Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2022-37978P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.217212022-10-11
CVE-2022-37978 [HIGH] CVE-2022-37978: Windows Active Directory Certificate Services Security Feature Bypass Windows Active Directory Certificate Services Security Feature Bypass
nvd
CVE-2024-43509P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43509 [HIGH] CWE-416 CVE-2024-43509: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-38141P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.222642023-09-12
CVE-2023-38141 [HIGH] CWE-367 CVE-2023-38141: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43644P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-43644 [HIGH] CWE-125 CVE-2024-43644: Windows Client-Side Caching Elevation of Privilege Vulnerability Windows Client-Side Caching Elevation of Privilege Vulnerability
nvd
CVE-2025-32716P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.233512025-06-10
CVE-2025-32716 [HIGH] CWE-125 CVE-2025-32716: Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally. Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49046P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-49046 [HIGH] CWE-367 CVE-2024-49046: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2023-21801P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21801 [HIGH] CVE-2023-21801: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2024-26228P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.226182024-04-09
CVE-2024-26228 [HIGH] CWE-310 CVE-2024-26228: Windows Cryptographic Services Security Feature Bypass Vulnerability Windows Cryptographic Services Security Feature Bypass Vulnerability
nvd
CVE-2025-49686P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-49686 [HIGH] CWE-476 CVE-2025-49686: Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges local Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd