Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Windows Server 2008 R2 Service Pack 1 — Vulnerabilities & Security Advisories 71

All 71 CVE vulnerabilities found in Windows Server 2008 R2 Service Pack 1, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities affecting the Microsoft Windows Server 2008 R2 Service Pack 1 operating system, categorized by their respective weakness types and security tags. It serves as a comprehensive repository for understanding the specific risk profiles associated with this legacy server environment. The content collected here encompasses a wide variety of vulnerability classifications, including remote code execution flaws, privilege escalation errors, information disclosure issues, and denial of service conditions. The time range covered spans from the initial release of the service pack through its end-of-support period, capturing both historical exploits and subsequently patched weaknesses during the product's active lifecycle. By reviewing this aggregation, readers can effectively track Microsoft’s security advisories as they were issued for this specific version, gaining insight into how different weakness classes manifested within the Windows Server 2008 R2 codebase. Furthermore, users can analyze the chronological history of vulnerabilities unique to this product release, allowing for a deeper understanding of its overall security posture and the evolution of threats it faced. This resource is intended for security analysts, system administrators, and compliance officers who need to assess the residual risk of maintaining or auditing systems running this operating system. The information provided aids in contextualizing patch management priorities and understanding the technical details behind specific CVE events without relying on external databases for raw data lookup.

Vendor: Microsoft

CVE IDTitleCVSSSeverityPublished
CVE-2025-49753 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 8.8 High2025-07-08
CVE-2025-49716 Windows Netlogon Denial of Service Vulnerability CWE-400 7.5 High2025-07-08
CVE-2025-49676 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 8.8 High2025-07-08
CVE-2025-49674 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 8.8 High2025-07-08
CVE-2025-49672 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 8.8 High2025-07-08
CVE-2025-49671 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability CWE-200 6.5 Medium2025-07-08
CVE-2025-49670 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 6.5 Medium2025-07-08
CVE-2025-48824 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 8.8 High2025-07-08
CVE-2025-49657 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 8.8 High2025-07-08
CVE-2025-32710 Windows Remote Desktop Services Remote Code Execution Vulnerability CWE-416 8.1 High2025-06-10
CVE-2025-29831 Windows Remote Desktop Services Remote Code Execution Vulnerability CWE-416 7.5 High2025-05-13
CVE-2025-29968 Active Directory Certificate Services (AD CS) Denial of Service Vulnerability CWE-20 6.5 Medium2025-05-13
CVE-2025-26676 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability CWE-126 6.5 Medium2025-04-08
CVE-2025-26671 Windows Remote Desktop Services Remote Code Execution Vulnerability CWE-416 8.1 High2025-04-08
CVE-2025-26647 Windows Kerberos Elevation of Privilege Vulnerability CWE-20 8.8 High2025-04-08
CVE-2025-21203 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability CWE-126 6.5 Medium2025-04-08
CVE-2025-27740 Active Directory Certificate Services Elevation of Privilege Vulnerability CWE-1390 8.8 High2025-04-08
CVE-2025-27474 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability CWE-908 6.5 Medium2025-04-08
CVE-2025-26667 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability CWE-200 6.5 Medium2025-04-08
CVE-2025-26664 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability CWE-126 6.5 Medium2025-04-08
CVE-2025-24064 Windows Domain Name Service Remote Code Execution Vulnerability CWE-416 8.1 High2025-03-11
CVE-2025-21410 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 8.8 High2025-02-11
CVE-2025-21208 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability CWE-122 8.8 High2025-02-11
CVE-2025-21297 Windows Remote Desktop Services Remote Code Execution Vulnerability CWE-416 8.1 High2025-01-14
CVE-2024-43456 Windows Remote Desktop Services Tampering Vulnerability CWE-284 4.8 Medium2024-10-08
CVE-2024-38260 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability CWE-908 8.8 High2024-09-10
CVE-2024-30075 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability CWE-122 8.0 High2024-06-11
CVE-2024-30074 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability CWE-122 8.0 High2024-06-11
CVE-2023-35379 Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability CWE-59 7.8 High2023-08-08
CVE-2023-36876 Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability CWE-59 7.1 High2023-08-08

All 71 known CVE vulnerabilities affecting Windows Server 2008 R2 Service Pack 1 with full Chinese analysis, references, and POCs where available.