Microsoft Windows Server Version 2004 vulnerabilities
747 known vulnerabilities affecting microsoft/windows_server_version_2004.
Total CVEs
747
CISA KEV
27
actively exploited
Public exploits
20
Exploited in wild
35
Severity breakdown
CRITICAL32HIGH535MEDIUM177LOW3
Vulnerabilities
Page 28 of 38
CVE-2020-0837P4MEDIUMCVSS 5.3≥ 10.0.0, < publication2020-09-11
CVE-2020-0837 [MEDIUM] CVE-2020-0837: <p>An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) i
An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication factors.
To exploit this vulnerability, an attacker could send a specially crafted authenticatio
nvd
CVE-2021-41332P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-41332 [MEDIUM] CVE-2021-41332: Windows Print Spooler Information Disclosure Vulnerability
Windows Print Spooler Information Disclosure Vulnerability
nvd
CVE-2021-38629P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.12372021-09-15
CVE-2021-38629 [MEDIUM] CVE-2021-38629: Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
nvd
CVE-2021-31186P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.9822021-05-11
CVE-2021-31186 [MEDIUM] CVE-2021-31186: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
nvd
CVE-2021-33744P4MEDIUMCVSS 6.7≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-33744 [MEDIUM] CVE-2021-33744: Windows Secure Kernel Mode Security Feature Bypass Vulnerability
Windows Secure Kernel Mode Security Feature Bypass Vulnerability
nvd
CVE-2021-34507P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-34507 [MEDIUM] CVE-2021-34507: Windows Remote Assistance Information Disclosure Vulnerability
Windows Remote Assistance Information Disclosure Vulnerability
nvd
CVE-2021-34444P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.11102021-07-16
CVE-2021-34444 [MEDIUM] CVE-2021-34444: Windows DNS Server Denial of Service Vulnerability
Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2020-0890P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0890 [MEDIUM] CVE-2020-0890: <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properl
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.
To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.
The sec
nvd
CVE-2020-16877P4HIGHCVSS 7.1≥ 10.0.0, < publication2020-10-16
CVE-2020-16877 [HIGH] CVE-2020-16877: <p>An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse
An elevation of privilege vulnerability exists when Microsoft Windows improperly handles reparse points. An attacker who successfully exploited this vulnerability could overwrite or delete a targeted file that would normally require elevated permissions.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2020-17014P4HIGHCVSS 7.1≥ 10.0.0, < publication2020-11-11
CVE-2020-17014 [HIGH] CVE-2020-17014: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
nvd
CVE-2021-33764P4MEDIUMCVSS 5.9≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-33764 [MEDIUM] CVE-2021-33764: Windows Key Distribution Center Information Disclosure Vulnerability
Windows Key Distribution Center Information Disclosure Vulnerability
nvd
CVE-2021-34493P4MEDIUMCVSS 6.7≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-34493 [MEDIUM] CWE-269 CVE-2021-34493: Windows Partition Management Driver Elevation of Privilege Vulnerability
Windows Partition Management Driver Elevation of Privilege Vulnerability
nvd
CVE-2021-41338P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-41338 [MEDIUM] CVE-2021-41338: Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
Windows AppContainer Firewall Rules Security Feature Bypass Vulnerability
nvd
CVE-2020-16919P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16919 [MEDIUM] CVE-2020-16919: <p>An information disclosure vulnerability exists when the Windows Enterprise App Management Service
An information disclosure vulnerability exists when the Windows Enterprise App Management Service improperly handles certain file operations. An attacker who successfully exploited this vulnerability could read arbitrary files.
An attacker with unprivileged access to a vulnerable system could exploit this vulnerability.
The security update addresses the vul
nvd
CVE-2021-33745P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-33745 [MEDIUM] CVE-2021-33745: Windows DNS Server Denial of Service Vulnerability
Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2021-34499P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-34499 [MEDIUM] CVE-2021-34499: Windows DNS Server Denial of Service Vulnerability
Windows DNS Server Denial of Service Vulnerability
nvd
CVE-2021-40463P4MEDIUMCVSS 6.5≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-40463 [MEDIUM] CVE-2021-40463: Windows Network Address Translation (NAT) Denial of Service Vulnerability
Windows Network Address Translation (NAT) Denial of Service Vulnerability
nvd
CVE-2020-16910P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16910 [MEDIUM] CWE-281 CVE-2020-16910: <p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creati
A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.
To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware
nvd
CVE-2021-42288P4MEDIUMCVSS 6.1≥ 10.0.0, < 10.0.19041.13482021-11-10
CVE-2021-42288 [MEDIUM] CVE-2021-42288: Windows Hello Security Feature Bypass Vulnerability
Windows Hello Security Feature Bypass Vulnerability
nvd
CVE-2020-1512P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1512 [MEDIUM] CVE-2020-1512: An information disclosure vulnerability exists when the Windows State Repository Service improperly
An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
T
nvd