cbcvebase.

Microsoft Windows Server 2008 Service Pack 2 vulnerabilities

1,672 known vulnerabilities affecting microsoft/windows_server_2008_service_pack_2.

Total CVEs
1,672
CISA KEV
66
actively exploited
Public exploits
61
Exploited in wild
86
Severity breakdown
CRITICAL68HIGH1214MEDIUM387LOW3

Vulnerabilities

Page 78 of 84
CVE-2026-20936P4MEDIUMCVSS 4.3≥ 6.0.6003.0, < 6.0.6003.237172026-01-13
CVE-2026-20936 [MEDIUM] CWE-125 CVE-2026-20936: Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a phys Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.
nvd
CVE-2023-24862P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.219662023-03-14
CVE-2023-24862 [MEDIUM] CWE-125 CVE-2023-24862: Windows Secure Channel Denial of Service Vulnerability Windows Secure Channel Denial of Service Vulnerability
nvd
CVE-2024-35270P4MEDIUMCVSS 5.3≥ 6.0.6003.0, < 6.0.6003.227692024-07-09
CVE-2024-35270 [MEDIUM] CWE-400 CVE-2024-35270: Windows iSCSI Service Denial of Service Vulnerability Windows iSCSI Service Denial of Service Vulnerability
nvd
CVE-2022-37981P4MEDIUMCVSS 4.3≥ 6.0.6003.0, < 6.0.6003.217212022-10-11
CVE-2022-37981 [MEDIUM] CVE-2022-37981: Windows Event Logging Service Denial of Service Vulnerability Windows Event Logging Service Denial of Service Vulnerability
nvd
CVE-2021-38631P4MEDIUMCVSS 4.4≥ 6.0.0, < 6.0.6003.212822021-11-10
CVE-2021-38631 [MEDIUM] CVE-2021-38631: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2021-41371P4MEDIUMCVSS 4.4≥ 6.0.0, < 6.0.6003.212822021-11-10
CVE-2021-41371 [MEDIUM] CVE-2021-41371: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2025-24055P4MEDIUMCVSS 4.3≥ 6.0.6003.0, < 6.0.6003.231682025-03-11
CVE-2025-24055 [MEDIUM] CWE-125 CVE-2025-24055: Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.
nvd
CVE-2022-22710P4MEDIUMCVSS 5.5≥ 6.0.6003.0, < 6.0.6003.213742022-02-09
CVE-2022-22710 [MEDIUM] CVE-2022-22710: Windows Common Log File System Driver Denial of Service Vulnerability Windows Common Log File System Driver Denial of Service Vulnerability
nvd
CVE-2021-28443P4MEDIUMCVSS 5.5≥ 6.0.0, < publication2021-04-13
CVE-2021-28443 [MEDIUM] CVE-2021-28443: Windows Console Driver Denial of Service Vulnerability Windows Console Driver Denial of Service Vulnerability
nvd
CVE-2022-21845P4MEDIUMCVSS 4.7≥ 6.0.6003.0, < 6.0.6003.215692022-07-12
CVE-2022-21845 [MEDIUM] CVE-2022-21845: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2025-21298CRITICALCVSS 9.8≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21298 [CRITICAL] CWE-416 Windows OLE Remote Code Execution Vulnerability Windows OLE Remote Code Execution Vulnerability Windows OLE Remote Code Execution Vulnerability
cvelistv5
CVE-2023-29325HIGHCVSS 8.1≥ 6.0.6003.0, < 6.0.6003.220702023-05-09
CVE-2023-29325 [HIGH] CWE-416 Windows OLE Remote Code Execution Vulnerability Windows OLE Remote Code Execution Vulnerability Windows OLE Remote Code Execution Vulnerability
cvelistv5
CVE-2024-21340P4MEDIUMCVSS 4.6≥ 6.0.6003.0, < 6.0.6003.225112024-02-13
CVE-2024-21340 [MEDIUM] CWE-126 CVE-2024-21340: Windows Kernel Information Disclosure Vulnerability Windows Kernel Information Disclosure Vulnerability
nvd
CVE-2025-29839P4MEDIUMCVSS 4.0≥ 6.0.6003.0, < 6.0.6003.232792025-05-13
CVE-2025-29839 [MEDIUM] CWE-125 CVE-2025-29839: Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information lo Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-59280P4LOWCVSS 3.1≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-59280 [LOW] CWE-287 CVE-2025-59280: Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering o Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
nvd
CVE-2025-21210P4MEDIUMCVSS 4.2≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21210 [MEDIUM] CWE-636 CVE-2025-21210: Windows BitLocker Information Disclosure Vulnerability Windows BitLocker Information Disclosure Vulnerability
nvd
CVE-2025-21214P4MEDIUMCVSS 4.2≥ 6.0.6003.0, < 6.0.6003.230702025-01-14
CVE-2025-21214 [MEDIUM] CWE-200 CVE-2025-21214: Windows BitLocker Information Disclosure Vulnerability Windows BitLocker Information Disclosure Vulnerability
nvd
CVE-2022-41076HIGHCVSS 8.5≥ 6.0.6003.0, < 6.0.6003.218152022-12-13
CVE-2022-41076 [HIGH] PowerShell Remote Code Execution Vulnerability PowerShell Remote Code Execution Vulnerability PowerShell Remote Code Execution Vulnerability
cvelistv5
CVE-2025-55695P4LOWCVSS 3.3≥ 6.0.6003.0, < 6.0.6003.235712025-10-14
CVE-2025-55695 [LOW] CWE-125 CVE-2025-55695: Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose inf Out-of-bounds read in Windows WLAN Auto Config Service allows an authorized attacker to disclose information locally.
nvd
CVE-2021-24086HIGHCVSS 7.5≥ 6.0.0, < publication2021-02-25
CVE-2021-24086 [HIGH] Windows TCP/IP Denial of Service Vulnerability Windows TCP/IP Denial of Service Vulnerability Windows TCP/IP Denial of Service Vulnerability
cvelistv5
Microsoft Windows Server 2008 Service Pack 2 vulnerabilities | cvebase