cbcvebase.

Microsoft Windows Server 2008 Service Pack 2 vulnerabilities

1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.

Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3

Vulnerabilities

Page 5 of 84
CVE-2023-29324P2MEDIUMCVSS 6.5Exploited≥ 6.0.6003.0, < 6.0.6003.220702023-05-09
CVE-2023-29324 [MEDIUM] CWE-73 CVE-2023-29324: Windows MSHTML Platform Security Feature Bypass Vulnerability Windows MSHTML Platform Security Feature Bypass Vulnerability
nvd
CVE-2023-28218P2HIGHCVSS 7.0Exploited≥ 6.0.6003.0, < 6.0.6003.220152023-04-11
CVE-2023-28218 [HIGH] CWE-122 CVE-2023-28218: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
nvd
CVE-2022-30170P2HIGHCVSS 7.3Exploited≥ 6.0.6003.0, < 6.0.6003.216662022-09-13
CVE-2022-30170 [HIGH] CVE-2022-30170: Windows Credential Roaming Service Elevation of Privilege Vulnerability Windows Credential Roaming Service Elevation of Privilege Vulnerability
nvd
CVE-2024-38063P1CRITICALCVSS 9.8PoC≥ 6.0.6003.0, < 6.0.6003.228252024-08-13
CVE-2024-38063 [CRITICAL] CWE-191 CVE-2024-38063: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2019-1150P2HIGHCVSS 8.8PoC≥ 6.0.0, < publication2019-08-14
CVE-2019-1150 [HIGH] CWE-787 CVE-2019-1150: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2024-38077P1CRITICALCVSS 9.8≥ 6.0.6003.0, < 6.0.6003.227692024-07-09
CVE-2024-38077 [CRITICAL] CWE-122 CVE-2024-38077: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
nvd
CVE-2019-1151P2HIGHCVSS 8.8PoC≥ 6.0.0, < publication2019-08-14
CVE-2019-1151 [HIGH] CWE-787 CVE-2019-1151: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2024-49112P1CRITICALCVSS 9.8≥ 6.0.6003.0, < 6.0.6003.230162024-12-12
CVE-2024-49112 [CRITICAL] CWE-190 CVE-2024-49112: Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
nvd
CVE-2022-26937P2CRITICALCVSS 9.8≥ 6.0.6003.0, < 6.0.6003.214812022-05-10
CVE-2022-26937 [CRITICAL] CVE-2022-26937: Windows Network File System Remote Code Execution Vulnerability Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2019-1149P2HIGHCVSS 8.8PoC≥ 6.0.0, < publication2019-08-14
CVE-2019-1149 [HIGH] CWE-787 CVE-2019-1149: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1144P2HIGHCVSS 8.8PoC≥ 6.0.0, < publication2019-08-14
CVE-2019-1144 [HIGH] CWE-415 CVE-2019-1144: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1152P2HIGHCVSS 8.8PoC≥ 6.0.0, < publication2019-08-14
CVE-2019-1152 [HIGH] CWE-787 CVE-2019-1152: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1145P2HIGHCVSS 8.8PoC≥ 6.0.0, < publication2019-08-14
CVE-2019-1145 [HIGH] CWE-119 CVE-2019-1145: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whos
nvd
CVE-2019-1019P2HIGHCVSS 8.5PoC≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1019 [HIGH] CWE-200 CVE-2019-1019: A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the sessio A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges. The issue
nvd
CVE-2021-26424P2CRITICALCVSS 9.8≥ 6.0.0, < 6.0.6003.211922021-08-12
CVE-2021-26424 [CRITICAL] CVE-2021-26424: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2022-34718P2CRITICALCVSS 9.8≥ 6.0.6003.0, < 6.0.6003.216662022-09-13
CVE-2022-34718 [CRITICAL] CVE-2022-34718: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2024-30080P2CRITICALCVSS 9.8≥ 6.0.6003.0, < 6.0.6003.227202024-06-11
CVE-2024-30080 [CRITICAL] CWE-416 CVE-2024-30080: Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
nvd
CVE-2022-21972P2HIGHCVSS 8.1≥ 6.0.6003.0, < 6.0.6003.214812022-05-10
CVE-2022-21972 [HIGH] CVE-2022-21972: Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
nvd
CVE-2021-28476P2CRITICALCVSS 9.9≥ 6.0.0, < 6.0.6003.211172021-05-11
CVE-2021-28476 [CRITICAL] CVE-2021-28476: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2025-50154P3MEDIUMCVSS 6.5PoC≥ 6.0.6003.0, < 6.0.6003.234712025-08-12
CVE-2025-50154 [MEDIUM] CWE-200 CVE-2025-50154: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauth Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd
Microsoft Windows Server 2008 Service Pack 2 vulnerabilities | cvebase