cbcvebase.

Microsoft Windows Server Version 2004 vulnerabilities

747 known vulnerabilities affecting microsoft/windows_server_version_2004.

Total CVEs
747
CISA KEV
27
actively exploited
Public exploits
20
Exploited in wild
35
Severity breakdown
CRITICAL32HIGH535MEDIUM177LOW3

Vulnerabilities

Page 30 of 38
CVE-2020-16921P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16921 [MEDIUM] CVE-2020-16921: <p>An information disclosure vulnerability exists in Text Services Framework when it fails to proper An information disclosure vulnerability exists in Text Services Framework when it fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could potentially read data that was not intended to be disclosed. Note that this vulnerability would not allow an attacker to execute code or to elevate their user rights dir
nvd
CVE-2020-16897P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16897 [MEDIUM] CVE-2020-16897: <p>An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) imp An information disclosure vulnerability exists when NetBIOS over TCP (NBT) Extensions (NetBT) improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have run a specially crafted application. The vulnerabi
nvd
CVE-2020-16854P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-16854 [MEDIUM] CVE-2020-16854: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
nvd
CVE-2020-1548P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1548 [MEDIUM] CVE-2020-1548: An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to improperly disclose memory. The security update addresses the vulnerability by correcting
nvd
CVE-2020-0989P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0989 [MEDIUM] CWE-862 CVE-2020-0989: <p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagno An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a
nvd
CVE-2020-0805P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0805 [MEDIUM] CVE-2020-0805: <p>A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly han A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a spe
nvd
CVE-2021-1656P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1656 [MEDIUM] CVE-2021-1656: TPM Device Driver Information Disclosure Vulnerability TPM Device Driver Information Disclosure Vulnerability
nvd
CVE-2021-24084P4MEDIUMCVSS 5.5≥ 10.0.0, < 10.0.19041.14152021-02-25
CVE-2021-24084 [MEDIUM] CWE-59 CVE-2021-24084: Windows Mobile Device Management Information Disclosure Vulnerability Windows Mobile Device Management Information Disclosure Vulnerability
nvd
CVE-2020-1474P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-08-17
CVE-2020-1474 [MEDIUM] CVE-2020-1474: An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service impr An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, an authenticated attacker could connect an imaging device (camera,
nvd
CVE-2020-1033P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-1033 [MEDIUM] CVE-2020-1033: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. An authenticated attacker could exploit this vulnerability by running a specially crafted application. The update addresses the
nvd
CVE-2020-0928P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-0928 [MEDIUM] CVE-2020-0928: <p>An information disclosure vulnerability exists when the Windows kernel improperly handles objects An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. T
nvd
CVE-2020-16879P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-09-11
CVE-2020-16879 [MEDIUM] CVE-2020-16879: <p>An information disclosure vulnerability exists when a Windows Projected Filesystem improperly han An information disclosure vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a s
nvd
CVE-2021-28311P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2021-04-13
CVE-2021-28311 [MEDIUM] CVE-2021-28311: Windows Application Compatibility Cache Denial of Service Vulnerability Windows Application Compatibility Cache Denial of Service Vulnerability
nvd
CVE-2021-1696P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1696 [MEDIUM] CVE-2021-1696: Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability
nvd
CVE-2021-28441P4MEDIUMCVSS 6.5≥ 10.0.0, < publication2021-04-13
CVE-2021-28441 [MEDIUM] CVE-2021-28441: Windows Hyper-V Information Disclosure Vulnerability Windows Hyper-V Information Disclosure Vulnerability
nvd
CVE-2021-1699P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1699 [MEDIUM] CVE-2021-1699: Windows (modem.sys) Information Disclosure Vulnerability Windows (modem.sys) Information Disclosure Vulnerability
nvd
CVE-2020-16940P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16940 [MEDIUM] CWE-269 CVE-2020-16940: <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) im An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then
nvd
CVE-2021-1672P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1672 [MEDIUM] CVE-2021-1672: Windows Projected File System FS Filter Driver Information Disclosure Vulnerability Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
nvd
CVE-2021-1670P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1670 [MEDIUM] CVE-2021-1670: Windows Projected File System FS Filter Driver Information Disclosure Vulnerability Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
nvd
CVE-2021-1663P4MEDIUMCVSS 5.5≥ 10.0.0, < publication2021-01-12
CVE-2021-1663 [MEDIUM] CVE-2021-1663: Windows Projected File System FS Filter Driver Information Disclosure Vulnerability Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
nvd
Microsoft Windows Server Version 2004 vulnerabilities | cvebase