Microsoft Windows Server 2008 Service Pack 2 vulnerabilities
1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.
Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
37
Exploited in wild
58
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3
Vulnerabilities
Page 76 of 84
CVE-2020-17098MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.209992020-12-09
CVE-2020-17098 [MEDIUM] Windows GDI+ Information Disclosure Vulnerability
Windows GDI+ Information Disclosure Vulnerability
Windows GDI+ Information Disclosure Vulnerability
cvelistv5
CVE-2020-17051CRITICALCVSS 9.8≥ 6.0.0, < publication2020-11-11
CVE-2020-17051 [CRITICAL] CVE-2020-17051: Windows Network File System Remote Code Execution Vulnerability
Windows Network File System Remote Code Execution Vulnerability
nvd
CVE-2020-17001HIGHCVSS 7.8≥ 6.0.0, < publication2020-11-11
CVE-2020-17001 [HIGH] CVE-2020-17001: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2020-17087HIGHCVSS 7.8KEV≥ 6.0.0, < publication2020-11-11
CVE-2020-17087 [HIGH] CWE-131 CVE-2020-17087: Windows Kernel Local Elevation of Privilege Vulnerability
Windows Kernel Local Elevation of Privilege Vulnerability
nvd
CVE-2020-17049HIGHCVSS 7.2≥ 6.0.0, < 6.0.6003.211672020-11-11
CVE-2020-17049 [HIGH] CWE-863 CVE-2020-17049: A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines i
A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD).
To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the K
nvd
CVE-2020-17042HIGHCVSS 8.8≥ 6.0.0, < publication2020-11-11
CVE-2020-17042 [HIGH] CVE-2020-17042: Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2020-17011HIGHCVSS 7.8≥ 6.0.0, < publication2020-11-11
CVE-2020-17011 [HIGH] CVE-2020-17011: Windows Port Class Library Elevation of Privilege Vulnerability
Windows Port Class Library Elevation of Privilege Vulnerability
nvd
CVE-2020-17088HIGHCVSS 7.8≥ 6.0.0, < publication2020-11-11
CVE-2020-17088 [HIGH] CVE-2020-17088: Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2020-17014HIGHCVSS 7.1≥ 6.0.0, < publication2020-11-11
CVE-2020-17014 [HIGH] CVE-2020-17014: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2020-17068HIGHCVSS 7.8≥ 6.0.0, < publication2020-11-11
CVE-2020-17068 [HIGH] Windows GDI+ Remote Code Execution Vulnerability
Windows GDI+ Remote Code Execution Vulnerability
Windows GDI+ Remote Code Execution Vulnerability
cvelistv5
CVE-2020-17043HIGHCVSS 7.8≥ 6.0.0, < publication2020-11-11
CVE-2020-17043 [HIGH] CVE-2020-17043: Windows Remote Access Elevation of Privilege Vulnerability
Windows Remote Access Elevation of Privilege Vulnerability
nvd
CVE-2020-17069MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-11-11
CVE-2020-17069 [MEDIUM] Windows NDIS Information Disclosure Vulnerability
Windows NDIS Information Disclosure Vulnerability
Windows NDIS Information Disclosure Vulnerability
cvelistv5
CVE-2020-17004MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-11-11
CVE-2020-17004 [MEDIUM] CVE-2020-17004: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2020-1599MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-11-11
CVE-2020-1599 [MEDIUM] Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
cvelistv5
CVE-2020-17045MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-11-11
CVE-2020-17045 [MEDIUM] CVE-2020-17045: Windows KernelStream Information Disclosure Vulnerability
Windows KernelStream Information Disclosure Vulnerability
nvd
CVE-2020-17036MEDIUMCVSS 5.5≥ 6.0.0, < publication2020-11-11
CVE-2020-17036 [MEDIUM] CVE-2020-17036: Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
Windows Function Discovery SSDP Provider Information Disclosure Vulnerability
nvd
CVE-2020-16900HIGHCVSS 7.8≥ 6.0.0, < publication2020-10-16
CVE-2020-16900 [HIGH] CVE-2020-16900: <p>An elevation of privilege vulnerability exists when the Windows Event System improperly handles o
An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to elevate privileges.
The security update addresses the vulnerability by correcting ho
nvd
CVE-2020-16891HIGHCVSS 8.8≥ 6.0.0, < publication2020-10-16
CVE-2020-16891 [HIGH] CWE-20 CVE-2020-16891: <p>A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to prope
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrar
nvd
CVE-2020-16887HIGHCVSS 7.8≥ 6.0.0, < publication2020-10-16
CVE-2020-16887 [HIGH] CVE-2020-16887: <p>An elevation of privilege vulnerability exists in the way that the Windows Network Connections Se
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update ad
nvd
CVE-2020-16924HIGHCVSS 7.8≥ 6.0.0, < publication2020-10-16
CVE-2020-16924 [HIGH] CVE-2020-16924: <p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly hand
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.
The update addresses the vulnerabi
nvd