cbcvebase.

Microsoft Windows Server Version 2004 vulnerabilities

747 known vulnerabilities affecting microsoft/windows_server_version_2004.

Total CVEs
747
CISA KEV
27
actively exploited
Public exploits
20
Exploited in wild
35
Severity breakdown
CRITICAL32HIGH535MEDIUM177LOW3

Vulnerabilities

Page 7 of 38
CVE-2020-1285P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1285 [HIGH] CVE-2020-1285: <p>A remote code execution vulnerability exists in the way that the Windows Graphics Device Interfac A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users who
nvd
CVE-2020-1509P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1509 [HIGH] CVE-2020-1509: An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LS An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service. The security update addresses the vul
nvd
CVE-2020-17049P3HIGHCVSS 7.2≥ 10.0.0, < 10.0.19041.11102020-11-11
CVE-2020-17049 [HIGH] CWE-863 CVE-2020-17049: A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines i A security feature bypass vulnerability exists in the way Key Distribution Center (KDC) determines if a service ticket can be used for delegation via Kerberos Constrained Delegation (KCD). To exploit the vulnerability, a compromised service that is configured to use KCD could tamper with a service ticket that is not valid for delegation to force the K
nvd
CVE-2021-24091P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-02-25
CVE-2021-24091 [HIGH] CWE-787 CVE-2021-24091: Windows Camera Codec Pack Remote Code Execution Vulnerability Windows Camera Codec Pack Remote Code Execution Vulnerability
nvd
CVE-2021-1694P3CRITICALCVSS 9.8≥ 10.0.0, < publication2021-01-12
CVE-2021-1694 [CRITICAL] CWE-269 CVE-2021-1694: Windows Update Stack Elevation of Privilege Vulnerability Windows Update Stack Elevation of Privilege Vulnerability
nvd
CVE-2020-0922P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-0922 [HIGH] CVE-2020-0922: <p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles ob A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript.
nvd
CVE-2020-1561P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1561 [HIGH] CVE-2020-1561: A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle ob A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correct
nvd
CVE-2020-1339P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-08-17
CVE-2020-1339 [HIGH] CVE-2020-1339: A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objec A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2021-42291P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.19041.13482021-11-10
CVE-2021-42291 [HIGH] CWE-269 CVE-2021-42291: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2021-42282P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.19041.13482021-11-10
CVE-2021-42282 [HIGH] CWE-269 CVE-2021-42282: Active Directory Domain Services Elevation of Privilege Vulnerability Active Directory Domain Services Elevation of Privilege Vulnerability
nvd
CVE-2020-1508P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1508 [HIGH] CVE-2020-1508: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2021-26867P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26867 [HIGH] CVE-2021-26867: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2020-16915P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-10-16
CVE-2020-16915 [HIGH] CWE-787 CVE-2020-16915: <p>A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convinc
nvd
CVE-2021-26443P3CRITICALCVSS 9.0≥ 10.0.0, < 10.0.19041.13482021-11-10
CVE-2021-26443 [CRITICAL] CVE-2021-26443: Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
nvd
CVE-2021-40461P3CRITICALCVSS 9.0≥ 10.0.0, < 10.0.19041.12882021-10-13
CVE-2021-40461 [CRITICAL] CVE-2021-40461: Windows Hyper-V Remote Code Execution Vulnerability Windows Hyper-V Remote Code Execution Vulnerability
nvd
CVE-2020-16899P3HIGHCVSS 7.5≥ 10.0.0, < publication2020-10-16
CVE-2020-16899 [HIGH] CVE-2020-16899: <p>A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 A denial of service vulnerability exists when the Windows TCP/IP stack improperly handles ICMPv6 Router Advertisement packets. An attacker who successfully exploited this vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to send specially crafted ICMPv6 Router Advertisement packets to a remote W
nvd
CVE-2020-1593P3HIGHCVSS 8.8≥ 10.0.0, < publication2020-09-11
CVE-2020-1593 [HIGH] CVE-2020-1593: <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user
nvd
CVE-2021-26876P3HIGHCVSS 8.8≥ 10.0.0, < publication2021-03-11
CVE-2021-26876 [HIGH] CVE-2021-26876: OpenType Font Parsing Remote Code Execution Vulnerability OpenType Font Parsing Remote Code Execution Vulnerability
nvd
CVE-2021-33750P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-33750 [HIGH] CVE-2021-33750: Windows DNS Snap-in Remote Code Execution Vulnerability Windows DNS Snap-in Remote Code Execution Vulnerability
nvd
CVE-2021-33749P3HIGHCVSS 8.8≥ 10.0.0, < 10.0.19041.11102021-07-14
CVE-2021-33749 [HIGH] CVE-2021-33749: Windows DNS Snap-in Remote Code Execution Vulnerability Windows DNS Snap-in Remote Code Execution Vulnerability
nvd
Microsoft Windows Server Version 2004 vulnerabilities | cvebase