Microsoft Windows Server Version 2004 vulnerabilities
747 known vulnerabilities affecting microsoft/windows_server_version_2004.
Total CVEs
747
CISA KEV
27
actively exploited
Public exploits
20
Exploited in wild
35
Severity breakdown
CRITICAL32HIGH535MEDIUM177LOW3
Vulnerabilities
Page 30 of 38
CVE-2020-16921P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16921 [MEDIUM] CVE-2020-16921: <p>An information disclosure vulnerability exists in Text Services Framework when it fails to proper
An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights dir
nvd
CVE-2020-16897P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16897 [MEDIUM] CVE-2020-16897: <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) imp
An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have run a specially crafted application. The vulnerabi
nvd
CVE-2020-16854P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-16854 [MEDIUM] CVE-2020-16854: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
nvd
CVE-2020-1548P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1548 [MEDIUM] CVE-2020-1548: An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles
An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory.
To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to improperly disclose memory.
The security update addresses the vulnerability by correcting
nvd
CVE-2020-0989P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0989 [MEDIUM] CWE-862 CVE-2020-0989: <p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagno
An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a
nvd
CVE-2020-0805P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0805 [MEDIUM] CVE-2020-0805: <p>A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly han
A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a spe
nvd
CVE-2021-1656P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1656 [MEDIUM] CVE-2021-1656: TPM Device Driver Information Disclosure Vulnerability
TPM Device Driver Information Disclosure Vulnerability
nvd
CVE-2021-24084P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19041.14152021-02-25
CVE-2021-24084 [MEDIUM] CWE-59 CVE-2021-24084: Windows Mobile Device Management Information Disclosure Vulnerability
Windows Mobile Device Management Information Disclosure Vulnerability
nvd
CVE-2020-1474P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1474 [MEDIUM] CVE-2020-1474: An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service impr
An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
To exploit the vulnerability, an authenticated attacker could connect an imaging device (camera,
nvd
CVE-2020-1033P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1033 [MEDIUM] CVE-2020-1033: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
An authenticated attacker could exploit this vulnerability by running a specially crafted application.
The update addresses the
nvd
CVE-2020-0928P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0928 [MEDIUM] CVE-2020-0928: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. T
nvd
CVE-2020-16879P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-16879 [MEDIUM] CVE-2020-16879: <p>An information disclosure vulnerability exists when a Windows Projected Filesystem improperly han
An information disclosure vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a s
nvd
CVE-2021-28311P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2021-04-13
CVE-2021-28311 [MEDIUM] CVE-2021-28311: Windows Application Compatibility Cache Denial of Service Vulnerability
Windows Application Compatibility Cache Denial of Service Vulnerability
nvd
CVE-2021-1696P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1696 [MEDIUM] CVE-2021-1696: Windows Graphics Component Information Disclosure Vulnerability
Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2021-28441P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2021-04-13
CVE-2021-28441 [MEDIUM] CVE-2021-28441: Windows Hyper-V Information Disclosure Vulnerability
Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2021-1699P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1699 [MEDIUM] CVE-2021-1699: Windows (modem.sys) Information Disclosure Vulnerability
Windows (modem.sys) Information Disclosure Vulnerability
nvd
CVE-2020-16940P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16940 [MEDIUM] CWE-269 CVE-2020-16940: <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) im
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2021-1672P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1672 [MEDIUM] CVE-2021-1672: Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
nvd
CVE-2021-1670P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1670 [MEDIUM] CVE-2021-1670: Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
nvd
CVE-2021-1663P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1663 [MEDIUM] CVE-2021-1663: Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
nvd