Known vulnerabilities in Windows Server 2008 SP2

Vendor: Microsoft
Version: 2008 SP2
Software CPE: cpe:2.3:o:microsoft:windows_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 419
Public exploits: 12
Known exploited (KEV): 20
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Windows Server version 2008 SP2 Windows Server 2008 SP2 is affected by 419 vulnerabilities: 7 critical, 130 high, 80 medium, 202 low Critical High Medium Low

Vulnerabilities (419)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119477 - Out-of-bounds read
CVE-2025-62462
CWE-125 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120980
#VU119476 - Out-of-bounds read
CVE-2025-62461
CWE-125 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120980
#VU119474 - Integer underflow
CVE-2025-62567
CWE-191 Medium
No
No
2008 6.0.6003.23666, 2012 R2 6.3.9600.22920, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120978
#VU119473 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-64661
CWE-362 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120977
#VU119471 - Heap-based Buffer Overflow
CVE-2025-64679
CWE-122 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 09.12.2025 SB2025120975
#VU119470 - Heap-based Buffer Overflow
CVE-2025-64680
CWE-122 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8519, 2019 10.0.17763.7919, 2022 23H2 10.0.25398.1913, 2022 10.0.20348.4294, 2025 10.0.26100.6899 09.12.2025 SB2025120975
#VU119469 - Missing Authentication for Critical Function
CVE-2025-59516
CWE-306 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120974
#VU119468 - Improper Access Control
CVE-2025-59517
CWE-284 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120974
#VU119467 - Improper Access Control
CVE-2025-64673
CWE-284 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120974
#VU119466 - Exposure of sensitive information to an unauthorized actor
CVE-2025-64670
CWE-200 Medium
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120973
#VU119465 - Out-of-bounds read
CVE-2025-62572
CWE-125 Low
No
No
2008 6.0.6003.23666, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120972
#VU119458 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-64658
CWE-362 Low
No
No
2008 6.0.6003.23666, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120966
#VU119457 - Use After Free
CVE-2025-62565
CWE-416 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120966
#VU119454 - Improper Access Control
CVE-2025-62570
CWE-284 Low
No
No
2008 6.0.6003.23666, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120963
#VU119450 - Use After Free
CVE-2025-62569
CWE-416 Low
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120959
#VU119449 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-62469
CWE-362 Low
No
No
2008 6.0.6003.23666, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120959
#VU119442 - Out-of-bounds read
CVE-2025-62468
CWE-125 Low
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120954
#VU119439 - Use After Free
CVE-2025-62573
CWE-416 Low
No
No
2008 6.0.6003.23666, 2016 10.0.14393.8688, 2019 10.0.17763.8146, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120950
#VU119437 - NULL Pointer Dereference
CVE-2025-62463
CWE-476 Low
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120950
#VU119436 - NULL Pointer Dereference
CVE-2025-62465
CWE-476 Low
No
No
2008 6.0.6003.23666, 2022 23H2 10.0.25398.2025, 2022 10.0.20348.4467, 2022 10.0.20348.4529, 2025 10.0.26100.7392, 2025 10.0.26100.7462 09.12.2025 SB2025120950


Showing elements 1 - 20 out of 419