cbcvebase.

Microsoft Windows Server Version 2004 vulnerabilities

747 known vulnerabilities affecting microsoft/windows_server_version_2004.

Total CVEs
747
CISA KEV
27
actively exploited
Public exploits
20
Exploited in wild
35
Severity breakdown
CRITICAL32HIGH535MEDIUM177LOW3

Vulnerabilities

Page 27 of 38
CVE-2021-40460P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-40460 [MEDIUM] CVE-2021-40460: Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability Windows Remote Procedure Call Runtime Security Feature Bypass Vulnerability
nvd
CVE-2020-1560P3HIGHCVSS 7.3vN/A2020-08-17
CVE-2020-1560 [HIGH] CVE-2020-1560: A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handle A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Exploitation of the vuln
nvd
CVE-2021-31205P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.9822021-05-11
CVE-2021-31205 [MEDIUM] CVE-2021-31205: Windows SMB Client Security Feature Bypass Vulnerability Windows SMB Client Security Feature Bypass Vulnerability
nvd
CVE-2021-38624P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.12882021-09-15
CVE-2021-38624 [MEDIUM] CWE-639 CVE-2021-38624: Windows Key Storage Provider Security Feature Bypass Vulnerability Windows Key Storage Provider Security Feature Bypass Vulnerability
nvd
CVE-2021-43219P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19041.14152021-12-15
CVE-2021-43219 [HIGH] CVE-2021-43219: DirectX Graphics Kernel File Denial of Service Vulnerability DirectX Graphics Kernel File Denial of Service Vulnerability
nvd
CVE-2021-31183P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-31183 [HIGH] CVE-2021-31183: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2021-26879P3HIGHCVSS 7.5≥ 10.0.0, < publication2021-03-11
CVE-2021-26879 [HIGH] CVE-2021-26879: Windows Network Address Translation (NAT) Denial of Service Vulnerability Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2021-34490P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-34490 [HIGH] CVE-2021-34490: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2021-33772P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-33772 [HIGH] CVE-2021-33772: Windows TCP/IP Driver Denial of Service Vulnerability Windows TCP/IP Driver Denial of Service Vulnerability
nvd
CVE-2020-1256P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1256 [MEDIUM] CVE-2020-1256: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a spe
nvd
CVE-2021-31968P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19041.10522021-06-08
CVE-2021-31968 [HIGH] CVE-2021-31968: Windows Remote Desktop Services Denial of Service Vulnerability Windows Remote Desktop Services Denial of Service Vulnerability
nvd
CVE-2021-33785P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-33785 [HIGH] CVE-2021-33785: Windows AF_UNIX Socket Provider Denial of Service Vulnerability Windows AF_UNIX Socket Provider Denial of Service Vulnerability
nvd
CVE-2020-1097P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1097 [MEDIUM] CVE-2020-1097: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2020-1228P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1228 [MEDIUM] CVE-2020-1228: <p>A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive. To exploit the vulnerability, an authenticated attacker could send malicious DNS queries to a target, resulting in a denial of service. The update addre
nvd
CVE-2020-1091P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1091 [MEDIUM] CVE-2020-1091: <p>An information disclosure vulnerability exists when the Windows GDI component improperly disclose An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a speci
nvd
CVE-2020-16997P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-11-11
CVE-2020-16997 [MEDIUM] CVE-2020-16997: Remote Desktop Protocol Server Information Disclosure Vulnerability Remote Desktop Protocol Server Information Disclosure Vulnerability
nvd
CVE-2020-1487P3MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1487 [MEDIUM] CVE-2020-1487: An information disclosure vulnerability exists when Media Foundation improperly handles objects in m An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log onto an affected system and open a specially crafted file. In a web-b
nvd
CVE-2021-43216P3MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.14152021-12-15
CVE-2021-43216 [MEDIUM] CWE-668 CVE-2021-43216: Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability
nvd
CVE-2021-43237P3HIGHCVSS 7.3≥ 10.0.0, < 10.0.19041.14152021-12-15
CVE-2021-43237 [HIGH] CWE-59 CVE-2021-43237: Windows Setup Elevation of Privilege Vulnerability Windows Setup Elevation of Privilege Vulnerability
nvd
CVE-2020-0875P3MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0875 [MEDIUM] CVE-2020-0875: <p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An atta An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity). This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to
nvd
Microsoft Windows Server Version 2004 vulnerabilities | cvebase