cbcvebase.

Microsoft Windows Server 2008 Service Pack 2 vulnerabilities

1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.

Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3

Vulnerabilities

Page 48 of 84
CVE-2020-1579P3HIGHCVSS 7.8≥ 6.0.0, < publication2020-08-17
CVE-2020-1579 [HIGH] CVE-2020-1579: An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider imp An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correc
nvd
CVE-2020-1587P3HIGHCVSS 7.8≥ 6.0.0, < publication2020-08-17
CVE-2020-1587 [HIGH] CVE-2020-1587: An elevation of privilege vulnerability exists when the Windows Ancillary Function Driver for WinSoc An elevation of privilege vulnerability exists when the Windows Ancillary Function Driver for WinSock improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by c
nvd
CVE-2021-40489P3HIGHCVSS 7.8≥ 6.0.0, < 6.0.6003.212512021-10-13
CVE-2021-40489 [HIGH] CWE-269 CVE-2021-40489: Storage Spaces Controller Elevation of Privilege Vulnerability Storage Spaces Controller Elevation of Privilege Vulnerability
nvd
CVE-2020-1538P3HIGHCVSS 7.8≥ 6.0.0, < publication2020-08-17
CVE-2020-1538 [HIGH] CVE-2020-1538: An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles An elevation of privilege vulnerability exists when the Windows UPnP Device Host improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correcting how the Wind
nvd
CVE-2020-1517P3HIGHCVSS 7.8≥ 6.0.0, < publication2020-08-17
CVE-2020-1517 [HIGH] CVE-2020-1517: An elevation of privilege vulnerability exists when the Windows File Server Resource Management Serv An elevation of privilege vulnerability exists when the Windows File Server Resource Management Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by
nvd
CVE-2020-0912P3HIGHCVSS 7.8≥ 6.0.0, < publication2020-09-11
CVE-2020-0912 [HIGH] CVE-2020-0912: <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges. The security update addresses the vulnerability by correct
nvd
CVE-2023-21817P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21817 [HIGH] CWE-287 CVE-2023-21817: Windows Kerberos Elevation of Privilege Vulnerability Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2021-1652P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-01-12
CVE-2021-1652 [HIGH] CWE-269 CVE-2021-1652: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1653P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-01-12
CVE-2021-1653 [HIGH] CWE-269 CVE-2021-1653: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1693P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-01-12
CVE-2021-1693 [HIGH] CWE-269 CVE-2021-1693: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1654P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-01-12
CVE-2021-1654 [HIGH] CWE-269 CVE-2021-1654: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2021-1655P3HIGHCVSS 7.8≥ 6.0.0, < publication2021-01-12
CVE-2021-1655 [HIGH] CWE-269 CVE-2021-1655: Windows CSC Service Elevation of Privilege Vulnerability Windows CSC Service Elevation of Privilege Vulnerability
nvd
CVE-2023-21822P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21822 [HIGH] CWE-416 CVE-2023-21822: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2023-36726P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.223172023-10-10
CVE-2023-36726 [HIGH] CWE-416 CVE-2023-36726: Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability Windows Internet Key Exchange (IKE) Extension Elevation of Privilege Vulnerability
nvd
CVE-2023-21805P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21805 [HIGH] CWE-77 CVE-2023-21805: Windows MSHTML Platform Remote Code Execution Vulnerability Windows MSHTML Platform Remote Code Execution Vulnerability
nvd
CVE-2025-27733P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-27733 [HIGH] CWE-125 CVE-2025-27733: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-21691P3HIGHCVSS 7.5≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21691 [HIGH] CWE-125 CVE-2023-21691: Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability Microsoft Protected Extensible Authentication Protocol (PEAP) Information Disclosure Vulnerability
nvd
CVE-2021-34514P3HIGHCVSS 7.8≥ 6.0.0, < 6.0.6003.211672021-07-14
CVE-2021-34514 [HIGH] CWE-269 CVE-2021-34514: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2022-24459P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.214162022-03-09
CVE-2022-24459 [HIGH] CVE-2022-24459: Windows Fax and Scan Service Elevation of Privilege Vulnerability Windows Fax and Scan Service Elevation of Privilege Vulnerability
nvd
CVE-2022-21834P3HIGHCVSS 7.8≥ 6.0.6003.0, < 6.0.6003.213492022-01-11
CVE-2022-21834 [HIGH] CVE-2022-21834: Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2008 Service Pack 2 vulnerabilities | cvebase