[1] - https://www.cvedetails.com/cve/CVE-2013-3175/
[2] - https://www.cvedetails.com/cve/CVE-2012-1852/
[3] - https://www.cvedetails.com/cve/CVE-2012-0173/
[4] - https://www.cvedetails.com/cve/CVE-2012-0002/
(Those were just the ones I quickly found that allow RCE on XP SP2 (the oldest thing that they still provided patches for, so most likely to be shared code with Win2k) without requiring active interaction on the target's behalf, e.g. not including "convince target to open X malformed file, receive payload")