Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 41 of 84
CVE-2024-38249P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.228702024-09-10
CVE-2024-38249 [HIGH] CWE-416 CVE-2024-38249: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2021-1657P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-01-12
CVE-2021-1657 [HIGH] CWE-269 CVE-2021-1657: Windows Fax Compose Form Remote Code Execution Vulnerability
Windows Fax Compose Form Remote Code Execution Vulnerability
nvd
CVE-2024-30094P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.227202024-06-11
CVE-2024-30094 [HIGH] CWE-122 CVE-2024-30094: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2022-24485P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.214462022-04-15
CVE-2022-24485 [HIGH] CVE-2022-24485: Win32 File Enumeration Remote Code Execution Vulnerability
Win32 File Enumeration Remote Code Execution Vulnerability
nvd
CVE-2024-38261P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-38261 [HIGH] CWE-20 CVE-2024-38261: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2024-43626P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-43626 [HIGH] CWE-122 CVE-2024-43626: Windows Telephony Service Elevation of Privilege Vulnerability
Windows Telephony Service Elevation of Privilege Vulnerability
nvd
CVE-2024-43556P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43556 [HIGH] CWE-416 CVE-2024-43556: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-30049P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.226682024-05-14
CVE-2024-30049 [HIGH] CWE-416 CVE-2024-30049: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2024-38079P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.227692024-07-09
CVE-2024-38079 [HIGH] CWE-122 CVE-2024-38079: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2024-38250P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.228702024-09-10
CVE-2024-38250 [HIGH] CWE-126 CVE-2024-38250: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2025-49689P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-49689 [HIGH] CWE-125 CVE-2025-49689: Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevat
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2022-37978P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.217212022-10-11
CVE-2022-37978 [HIGH] CVE-2022-37978: Windows Active Directory Certificate Services Security Feature Bypass
Windows Active Directory Certificate Services Security Feature Bypass
nvd
CVE-2024-43509P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43509 [HIGH] CWE-416 CVE-2024-43509: Windows Graphics Component Elevation of Privilege Vulnerability
Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-38141P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.222642023-09-12
CVE-2023-38141 [HIGH] CWE-367 CVE-2023-38141: Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2024-43644P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-43644 [HIGH] CWE-125 CVE-2024-43644: Windows Client-Side Caching Elevation of Privilege Vulnerability
Windows Client-Side Caching Elevation of Privilege Vulnerability
nvd
CVE-2025-32716P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.233512025-06-10
CVE-2025-32716 [HIGH] CWE-125 CVE-2025-32716: Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Media allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49046P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-49046 [HIGH] CWE-367 CVE-2024-49046: Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
nvd
CVE-2023-21801P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21801 [HIGH] CVE-2023-21801: Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
nvd
CVE-2024-26228P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.226182024-04-09
CVE-2024-26228 [HIGH] CWE-310 CVE-2024-26228: Windows Cryptographic Services Security Feature Bypass Vulnerability
Windows Cryptographic Services Security Feature Bypass Vulnerability
nvd
CVE-2025-49686P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-49686 [HIGH] CWE-476 CVE-2025-49686: Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges local
Null pointer dereference in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
nvd