cbcvebase.

Microsoft Windows Server Version 2004 vulnerabilities

747 known vulnerabilities affecting microsoft/windows_server_version_2004.

Total CVEs
747
CISA KEV
27
actively exploited
Public exploits
20
Exploited in wild
35
Severity breakdown
CRITICAL32HIGH535MEDIUM177LOW3

Vulnerabilities

Page 2 of 38
CVE-2021-31201P1HIGHCVSS 7.8KEV≥ 10.0.0, < 10.0.19041.10522021-06-08
CVE-2021-31201 [HIGH] CVE-2021-31201: Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability
nvd
CVE-2021-40449HIGHCVSS 7.8KEVPoCRansomware≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-40449 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-36942HIGHCVSS 7.5KEVPoCRansomware≥ 10.0.0, < 10.0.19041.11652021-08-12
CVE-2021-36942 [HIGH] Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability Windows LSA Spoofing Vulnerability
cvelistv5
CVE-2021-31956HIGHCVSS 7.8KEVPoC≥ 10.0.0, < 10.0.19041.10522021-06-08
CVE-2021-31956 [HIGH] Windows NTFS Elevation of Privilege Vulnerability Windows NTFS Elevation of Privilege Vulnerability Windows NTFS Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-34481P1CRITICALCVSS 9.8ExploitedRansomware≥ 10.0.0, < 10.0.19041.11652021-07-16
CVE-2021-34481 [CRITICAL] CWE-269 CVE-2021-34481: <p>A remote code execution vulnerability exists when the Windows Print Spooler service improperly pe A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user r
nvd
CVE-2021-26897P1CRITICALCVSS 9.8Exploited≥ 10.0.0, < publication2021-03-11
CVE-2021-26897 [CRITICAL] CVE-2021-26897: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
CVE-2021-28310HIGHCVSS 7.8KEV≥ 10.0.0, < publication2021-04-13
CVE-2021-28310 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-41357HIGHCVSS 7.8KEV≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-41357 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2021-40450HIGHCVSS 7.8KEV≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-40450 [HIGH] Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability Win32k Elevation of Privilege Vulnerability
cvelistv5
CVE-2020-16896P1HIGHCVSS 7.5ExploitedRansomware≥ 10.0.0, < publication2020-10-16
CVE-2020-16896 [HIGH] CVE-2020-16896: <p>An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would need to run a
nvd
CVE-2021-43207P1HIGHCVSS 7.8ExploitedRansomware≥ 10.0.0, < 10.0.19041.14152021-12-15
CVE-2021-43207 [HIGH] CVE-2021-43207: Windows Common Log File System Driver Elevation of Privilege Vulnerability Windows Common Log File System Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-31969P2HIGHCVSS 7.8Exploited≥ 10.0.0, < 10.0.19041.10522021-06-08
CVE-2021-31969 [HIGH] CWE-269 CVE-2021-31969: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-28442P2MEDIUMCVSS 6.5Exploited≥ 10.0.0, < publication2021-04-13
CVE-2021-28442 [MEDIUM] CVE-2021-28442: Windows TCP/IP Information Disclosure Vulnerability Windows TCP/IP Information Disclosure Vulnerability
nvd
CVE-2021-26424P2CRITICALCVSS 9.8≥ 10.0.0, < 10.0.19041.11652021-08-12
CVE-2021-26424 [CRITICAL] CVE-2021-26424: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2021-28476P2CRITICALCVSS 9.9≥ 10.0.0, < 10.0.19041.9822021-05-11
CVE-2021-28476 [CRITICAL] CVE-2021-28476: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2020-1337P3HIGHCVSS 7.8PoC≥ 10.0.0, < publication2020-08-17
CVE-2020-1337 [HIGH] CWE-367 CVE-2020-1337: An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly all An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or delete data; or create new accounts wit
nvd
CVE-2020-17136P3HIGHCVSS 7.8PoC≥ 10.0.0, < publication2020-12-10
CVE-2020-17136 [HIGH] CVE-2020-17136: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-24074P2CRITICALCVSS 9.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24074 [CRITICAL] CVE-2021-24074: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2021-24094P2CRITICALCVSS 9.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24094 [CRITICAL] CVE-2021-24094: Windows TCP/IP Remote Code Execution Vulnerability Windows TCP/IP Remote Code Execution Vulnerability
nvd
CVE-2021-26877P2CRITICALCVSS 9.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26877 [CRITICAL] CVE-2021-26877: Windows DNS Server Remote Code Execution Vulnerability Windows DNS Server Remote Code Execution Vulnerability
nvd
Microsoft Windows Server Version 2004 vulnerabilities | cvebase