cbcvebase.

Microsoft Windows Server 2008 Service Pack 2 vulnerabilities

1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.

Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3

Vulnerabilities

Page 67 of 84
CVE-2023-28222P4HIGHCVSS 7.1≥ 6.0.6003.0, < 6.0.6003.220152023-04-11
CVE-2023-28222 [HIGH] CWE-59 CVE-2023-28222: Windows Kernel Elevation of Privilege Vulnerability Windows Kernel Elevation of Privilege Vulnerability
nvd
CVE-2019-1178P4HIGHCVSS 7.0≥ 6.0.0, < publication2019-08-14
CVE-2019-1178 [HIGH] CVE-2019-1178: An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in me An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability
nvd
CVE-2022-30225P4HIGHCVSS 7.1≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-30225 [HIGH] CVE-2022-30225: Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability
nvd
CVE-2019-1177P4HIGHCVSS 7.0≥ 6.0.0, < publication2019-08-14
CVE-2019-1177 [HIGH] CWE-269 CVE-2019-1177: An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memo An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerab
nvd
CVE-2024-43534P4MEDIUMCVSS 6.5≥ 6.0.6003.0, < 6.0.6003.229182024-10-08
CVE-2024-43534 [MEDIUM] CWE-125 CVE-2024-43534: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2025-50158P4HIGHCVSS 7.0≥ 6.0.6003.0, < 6.0.6003.234712025-08-12
CVE-2025-50158 [HIGH] CWE-367 CVE-2025-50158: Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-29368P4HIGHCVSS 7.0≥ 6.0.6003.0, < 6.0.6003.221132023-06-14
CVE-2023-29368 [HIGH] CWE-415 CVE-2023-29368: Windows Filtering Platform Elevation of Privilege Vulnerability Windows Filtering Platform Elevation of Privilege Vulnerability
nvd
CVE-2023-28216P4HIGHCVSS 7.0≥ 6.0.6003.0, < 6.0.6003.220152023-04-11
CVE-2023-28216 [HIGH] CVE-2023-28216: Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
nvd
CVE-2023-23385P4HIGHCVSS 7.0≥ 6.0.6003.0, < 6.0.6003.219662023-03-14
CVE-2023-23385 [HIGH] CWE-190 CVE-2023-23385: Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability Windows Point-to-Point Protocol over Ethernet (PPPoE) Elevation of Privilege Vulnerability
nvd
CVE-2023-21542P4HIGHCVSS 7.0≥ 6.0.6003.0, < 6.0.6003.218722023-01-10
CVE-2023-21542 [HIGH] CWE-59 CVE-2023-21542: Windows Installer Elevation of Privilege Vulnerability Windows Installer Elevation of Privilege Vulnerability
nvd
CVE-2022-30205P4MEDIUMCVSS 6.6≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-30205 [MEDIUM] CWE-362 CVE-2022-30205: Windows Group Policy Elevation of Privilege Vulnerability Windows Group Policy Elevation of Privilege Vulnerability
nvd
CVE-2026-20821P4MEDIUMCVSS 6.2≥ 6.0.6003.0, < 6.0.6003.237172026-01-13
CVE-2026-20821 [MEDIUM] CWE-200 CVE-2026-20821: Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows a Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.
nvd
CVE-2022-21924P4MEDIUMCVSS 5.3≥ 6.0.6003.0, < 6.0.6003.213492022-01-11
CVE-2022-21924 [MEDIUM] CVE-2022-21924: Workstation Service Remote Protocol Security Feature Bypass Vulnerability Workstation Service Remote Protocol Security Feature Bypass Vulnerability
nvd
CVE-2025-27471P4MEDIUMCVSS 5.9≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-27471 [MEDIUM] CWE-591 CVE-2025-27471: Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthor Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-36713P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.223172023-10-10
CVE-2023-36713 [MEDIUM] CWE-908 CVE-2023-36713: Windows Common Log File System Driver Information Disclosure Vulnerability Windows Common Log File System Driver Information Disclosure Vulnerability
nvd
CVE-2021-34507P4MEDIUMCVSS 6.5≥ 6.0.0, < 6.0.6003.211672021-07-14
CVE-2021-34507 [MEDIUM] CVE-2021-34507: Windows Remote Assistance Information Disclosure Vulnerability Windows Remote Assistance Information Disclosure Vulnerability
nvd
CVE-2021-34444P4MEDIUMCVSS 6.5≥ 6.0.0, < 6.0.6003.211672021-07-16
CVE-2021-34444 [MEDIUM] CVE-2021-34444: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2022-26934P4MEDIUMCVSS 6.5≥ 6.0.6003.0, < 6.0.6003.214812022-05-10
CVE-2022-26934 [MEDIUM] CVE-2022-26934: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2019-0713P4MEDIUMCVSS 6.8≥ 6.0.0, < publication≥ 6.0.6003.0, < publication2019-06-12
CVE-2019-0713 [MEDIUM] CWE-20 CVE-2019-0713: A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly v A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that cau
nvd
CVE-2020-17014P4HIGHCVSS 7.1≥ 6.0.0, < publication2020-11-11
CVE-2020-17014 [HIGH] CVE-2020-17014: Windows Print Spooler Elevation of Privilege Vulnerability Windows Print Spooler Elevation of Privilege Vulnerability
nvd
Microsoft Windows Server 2008 Service Pack 2 vulnerabilities | cvebase