Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 73 of 84
CVE-2019-1039P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1039 [MEDIUM] CWE-665 CVE-2019-1039: An information disclosure vulnerability exists when the Windows kernel improperly initializes object
An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.
To exploit this vulnerability, an authenticated attacker could run a specially crafted application. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
The update addre
nvd
CVE-2023-36801P4MEDIUMCVSS 5.3≥ 6.0.6003.0, < 6.0.6003.222642023-09-12
CVE-2023-36801 [MEDIUM] CWE-126 CVE-2023-36801: DHCP Server Service Information Disclosure Vulnerability
DHCP Server Service Information Disclosure Vulnerability
nvd
CVE-2025-24992P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.231682025-03-11
CVE-2025-24992 [MEDIUM] CWE-126 CVE-2025-24992: Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2023-21682P4MEDIUMCVSS 5.3≥ 6.0.6003.0, < 6.0.6003.218722023-01-10
CVE-2023-21682 [MEDIUM] CWE-125 CVE-2023-21682: Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
Windows Point-to-Point Protocol (PPP) Information Disclosure Vulnerability
nvd
CVE-2024-38256P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.228702024-09-10
CVE-2024-38256 [MEDIUM] CWE-908 CVE-2024-38256: Windows Kernel-Mode Driver Information Disclosure Vulnerability
Windows Kernel-Mode Driver Information Disclosure Vulnerability
nvd
CVE-2023-21699P4MEDIUMCVSS 5.3≥ 6.0.6003.0, < 6.0.6003.219152023-02-14
CVE-2023-21699 [MEDIUM] CWE-125 CVE-2023-21699: Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
Windows Internet Storage Name Service (iSNS) Server Information Disclosure Vulnerability
nvd
CVE-2025-49658P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.234182025-07-08
CVE-2025-49658 [MEDIUM] CWE-125 CVE-2025-49658: Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows TDX.sys allows an authorized attacker to disclose information locally.
nvd
CVE-2025-21268P4MEDIUMCVSS 4.3≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21268 [MEDIUM] CWE-41 CVE-2025-21268: MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
nvd
CVE-2026-20834P4MEDIUMCVSS 4.6≥ 6.0.6003.0, < 6.0.6003.237172026-01-13
CVE-2026-20834 [MEDIUM] CWE-36 CVE-2026-20834: Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
nvd
CVE-2021-1696P4MEDIUMCVSS 5.5≥ 6.0.0, < publication2021-01-12
CVE-2021-1696 [MEDIUM] CVE-2021-1696: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2025-58717P4MEDIUMCVSS 4.3≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-58717 [MEDIUM] CWE-125 CVE-2025-58717: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-55700P4MEDIUMCVSS 4.3≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-55700 [MEDIUM] CWE-125 CVE-2025-55700: Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attack
Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-54107P4MEDIUMCVSS 4.3≥ 6.0.6003.0, < 6.0.6003.235292025-09-09
CVE-2025-54107 [MEDIUM] CWE-41 CVE-2025-54107: Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to b
Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2025-54917P4MEDIUMCVSS 4.3≥ 6.0.6003.0, < 6.0.6003.235292025-09-09
CVE-2025-54917 [MEDIUM] CWE-693 CVE-2025-54917: Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a sec
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-35642P4MEDIUMCVSS 6.5≥ 6.0.6003.0, < 6.0.6003.224132023-12-12
CVE-2023-35642 [MEDIUM] CWE-682 CVE-2023-35642: Internet Connection Sharing (ICS) Denial of Service Vulnerability
Internet Connection Sharing (ICS) Denial of Service Vulnerability
nvd
CVE-2019-1010P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1010 [MEDIUM] CWE-200 CVE-2019-1010: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-0977P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-0977 [MEDIUM] CWE-200 CVE-2019-0977: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1048P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1048 [MEDIUM] CWE-200 CVE-2019-1048: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1015P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1015 [MEDIUM] CWE-200 CVE-2019-1015: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1011P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1011 [MEDIUM] CWE-200 CVE-2019-1011: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd