Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 74 of 84
CVE-2019-1016P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1016 [MEDIUM] CWE-200 CVE-2019-1016: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1012P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1012 [MEDIUM] CWE-200 CVE-2019-1012: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1046P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1046 [MEDIUM] CWE-200 CVE-2019-1046: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1049P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1049 [MEDIUM] CWE-200 CVE-2019-1049: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2019-1047P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < publication≥ 6.0.0, < publication2019-06-12
CVE-2019-1047 [MEDIUM] CWE-200 CVE-2019-1047: An information disclosure vulnerability exists when the Windows GDI component improperly discloses t
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to op
nvd
CVE-2021-1699P4MEDIUMCVSS 5.5≥ 6.0.0, < publication2021-01-12
CVE-2021-1699 [MEDIUM] CVE-2021-1699: Windows (modem.sys) Information Disclosure Vulnerability
Windows (modem.sys) Information Disclosure Vulnerability
nvd
CVE-2020-16940P4MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-10-16
CVE-2020-16940 [MEDIUM] CWE-269 CVE-2020-16940: <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) im
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2023-28271P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.220152023-04-11
CVE-2023-28271 [MEDIUM] CWE-200 CVE-2023-28271: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2020-1083P4MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-09-11
CVE-2020-1083 [MEDIUM] CVE-2020-1083: <p>An information disclosure vulnerability exists when the Microsoft Windows Graphics Component impr
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially c
nvd
CVE-2020-1250P4MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-09-11
CVE-2020-1250 [MEDIUM] CVE-2020-1250: <p>An information disclosure vulnerability exists when the win32k component improperly provides kern
An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application
nvd
CVE-2025-21320P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21320 [MEDIUM] CWE-532 CVE-2025-21320: Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
nvd
CVE-2025-27742P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.232202025-04-08
CVE-2025-27742 [MEDIUM] CWE-125 CVE-2025-27742: Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-30039P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.226682024-05-14
CVE-2024-30039 [MEDIUM] CWE-126 CVE-2024-30039: Windows Remote Access Connection Manager Information Disclosure Vulnerability
Windows Remote Access Connection Manager Information Disclosure Vulnerability
nvd
CVE-2024-38203P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.229662024-11-12
CVE-2024-38203 [MEDIUM] CWE-693 CVE-2024-38203: Windows Package Library Manager Information Disclosure Vulnerability
Windows Package Library Manager Information Disclosure Vulnerability
nvd
CVE-2024-38118P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.228252024-08-13
CVE-2024-38118 [MEDIUM] CWE-908 CVE-2024-38118: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2024-38122P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.228252024-08-13
CVE-2024-38122 [MEDIUM] CWE-908 CVE-2024-38122: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2025-59190P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-59190 [MEDIUM] CWE-20 CVE-2025-59190: Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to d
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
nvd
CVE-2023-23394P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.219662023-03-14
CVE-2023-23394 [MEDIUM] CWE-822 CVE-2023-23394: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2023-23409P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.219662023-03-14
CVE-2023-23409 [MEDIUM] CWE-20 CVE-2023-23409: Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability
nvd
CVE-2024-20662P4MEDIUMCVSS 4.9≥ 6.0.6003.0, < 6.0.6003.224642024-01-09
CVE-2024-20662 [MEDIUM] CWE-843 CVE-2024-20662: Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability
nvd