cbcvebase.

Microsoft Windows Server 2008 Service Pack 2 vulnerabilities

1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.

Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3

Vulnerabilities

Page 69 of 84
CVE-2021-34499P4MEDIUMCVSS 6.5≥ 6.0.0, < 6.0.6003.211672021-07-14
CVE-2021-34499 [MEDIUM] CVE-2021-34499: Windows DNS Server Denial of Service Vulnerability Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2022-35759P4MEDIUMCVSS 6.5≥ 6.0.6003.0, < 6.0.6003.216162023-05-31
CVE-2022-35759 [MEDIUM] CVE-2022-35759: Windows Local Security Authority (LSA) Denial of Service Vulnerability Windows Local Security Authority (LSA) Denial of Service Vulnerability
nvd
CVE-2023-35321P4MEDIUMCVSS 6.5≥ 6.0.6003.0, < 6.0.6003.221752023-07-11
CVE-2023-35321 [MEDIUM] CWE-170 CVE-2023-35321: Windows Deployment Services Denial of Service Vulnerability Windows Deployment Services Denial of Service Vulnerability
nvd
CVE-2024-43634P4MEDIUMCVSS 6.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-43634 [MEDIUM] CWE-125 CVE-2024-43634: Windows USB Video Class System Driver Elevation of Privilege Vulnerability Windows USB Video Class System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43637P4MEDIUMCVSS 6.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-43637 [MEDIUM] CWE-125 CVE-2024-43637: Windows USB Video Class System Driver Elevation of Privilege Vulnerability Windows USB Video Class System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43638P4MEDIUMCVSS 6.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-43638 [MEDIUM] CWE-125 CVE-2024-43638: Windows USB Video Class System Driver Elevation of Privilege Vulnerability Windows USB Video Class System Driver Elevation of Privilege Vulnerability
nvd
CVE-2024-43643P4MEDIUMCVSS 6.8≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-43643 [MEDIUM] CWE-125 CVE-2024-43643: Windows USB Video Class System Driver Elevation of Privilege Vulnerability Windows USB Video Class System Driver Elevation of Privilege Vulnerability
nvd
CVE-2025-24987P4MEDIUMCVSS 6.8≥ 6.0.6003.0, < 6.0.6003.231682025-03-11
CVE-2025-24987 [MEDIUM] CWE-125 CVE-2025-24987: Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges w Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
nvd
CVE-2025-24988P4MEDIUMCVSS 6.8≥ 6.0.6003.0, < 6.0.6003.231682025-03-11
CVE-2025-24988 [MEDIUM] CWE-125 CVE-2025-24988: Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges w Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
nvd
CVE-2022-38032P4MEDIUMCVSS 6.6≥ 6.0.6003.0, < 6.0.6003.217212022-10-11
CVE-2022-38032 [MEDIUM] CVE-2022-38032: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2023-32055P4MEDIUMCVSS 6.7≥ 6.0.6003.0, < 6.0.6003.221752023-07-11
CVE-2023-32055 [MEDIUM] CWE-416 CVE-2023-32055: Active Template Library Elevation of Privilege Vulnerability Active Template Library Elevation of Privilege Vulnerability
nvd
CVE-2022-22023P4MEDIUMCVSS 6.6≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-22023 [MEDIUM] CVE-2022-22023: Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability
nvd
CVE-2025-47980P4MEDIUMCVSS 6.2≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-47980 [MEDIUM] CWE-200 CVE-2025-47980: Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an un Exposure of sensitive information to an unauthorized actor in Windows Imaging Component allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-24900P4MEDIUMCVSS 5.9≥ 6.0.6003.0, < 6.0.6003.220702023-05-09
CVE-2023-24900 [MEDIUM] CWE-125 CVE-2023-24900: Windows NTLM Security Support Provider Information Disclosure Vulnerability Windows NTLM Security Support Provider Information Disclosure Vulnerability
nvd
CVE-2026-20833P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.237172026-01-13
CVE-2026-20833 [MEDIUM] CWE-327 CVE-2026-20833: Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker t Use of a broken or risky cryptographic algorithm in Windows Kerberos allows an authorized attacker to disclose information locally.
nvd
CVE-2019-0968P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-0968 [MEDIUM] CVE-2019-0968: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2019-1013P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1013 [MEDIUM] CWE-200 CVE-2019-1013: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1053P4MEDIUMCVSS 6.3≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1053 [MEDIUM] CWE-59 CVE-2019-1053: An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder short An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would require unprivileged execution on the victim system. The security update addresses the vulnera
nvd
CVE-2020-16914P4MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-10-16
CVE-2020-16914 [MEDIUM] CVE-2020-16914: <p>An information disclosure vulnerability exists in the way that the Windows Graphics Device Interf An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses i
nvd
CVE-2025-29974P4MEDIUMCVSS 5.7≥ 6.0.6003.0, < 6.0.6003.232792025-05-13
CVE-2025-29974 [MEDIUM] CWE-125 CVE-2025-29974: Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose Integer underflow (wrap or wraparound) in Windows Kernel allows an unauthorized attacker to disclose information over an adjacent network.
nvd
Microsoft Windows Server 2008 Service Pack 2 vulnerabilities | cvebase