Microsoft Windows Server 2004
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Windows Server 2004.
By the Year
In 2026 there have been 1 vulnerability in Microsoft Windows Server 2004 with an average score of 6.5 out of ten. Windows Server 2004 did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 6.50 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 218 | 7.42 |
| 2020 | 147 | 7.17 |
It may take a day or so for new Windows Server 2004 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Windows Server 2004 Security Vulnerabilities
Jun 2026: Windows NTLM Spoofing Vulnerability
CVE-2026-50508
6.5 - Medium
- June 09, 2026
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Information Disclosure
Dec 2021: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-43226
7.8 - High
- December 15, 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Nov 2021: Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42278
7.5 - High
- November 10, 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
Nov 2021: Windows Installer Elevation of Privilege Vulnerability
CVE-2021-41379
5.5 - Medium
- November 10, 2021
Windows Installer Elevation of Privilege Vulnerability
insecure temporary file
Nov 2021: Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42287
7.5 - High
- November 10, 2021
Active Directory Domain Services Elevation of Privilege Vulnerability
Windows Nearby Sharing Elevation of Privilege Vulnerability
CVE-2021-40464
8 - High
- October 13, 2021
Windows Nearby Sharing Elevation of Privilege Vulnerability
Improper Privilege Management
Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution Vulnerability
CVE-2021-40462
7.8 - High
- October 13, 2021
Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution Vulnerability
Windows Text Shaping Remote Code Execution Vulnerability
CVE-2021-40465
7.8 - High
- October 13, 2021
Windows Text Shaping Remote Code Execution Vulnerability
Oct 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-41357
7.8 - High
- October 13, 2021
Win32k Elevation of Privilege Vulnerability
Oct 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-40450
7.8 - High
- October 13, 2021
Win32k Elevation of Privilege Vulnerability
Oct 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-40449
7.8 - High
- October 13, 2021
Win32k Elevation of Privilege Vulnerability
Dangling pointer
Sep 2021: Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-40447
7.8 - High
- September 15, 2021
Windows Print Spooler Elevation of Privilege Vulnerability
Sep 2021: Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38671
7.8 - High
- September 15, 2021
Windows Print Spooler Elevation of Privilege Vulnerability
Sep 2021: Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38667
7.8 - High
- September 15, 2021
Windows Print Spooler Elevation of Privilege Vulnerability
Sep 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-38639
7.8 - High
- September 15, 2021
Win32k Elevation of Privilege Vulnerability
Sep 2021: Windows Storage Information Disclosure Vulnerability
CVE-2021-38637
5.5 - Medium
- September 15, 2021
Windows Storage Information Disclosure Vulnerability
Sep 2021: Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-38636
5.5 - Medium
- September 15, 2021
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
Sep 2021: Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-38635
5.5 - Medium
- September 15, 2021
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
Sep 2021: Microsoft Windows Update Client Elevation of Privilege Vulnerability
CVE-2021-38634
7.1 - High
- September 15, 2021
Microsoft Windows Update Client Elevation of Privilege Vulnerability
Sep 2021: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-38633
7.8 - High
- September 15, 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Sep 2021: Windows BitLocker Security Feature Bypass Vulnerability
CVE-2021-38632
5.7 - Medium
- September 15, 2021
Windows BitLocker Security Feature Bypass Vulnerability
Sep 2021: Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-38630
7.8 - High
- September 15, 2021
Windows Event Tracing Elevation of Privilege Vulnerability
Sep 2021: Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
CVE-2021-38629
6.5 - Medium
- September 15, 2021
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
Sep 2021: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38628
7.8 - High
- September 15, 2021
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Sep 2021: Windows Key Storage Provider Security Feature Bypass Vulnerability
CVE-2021-38624
6.5 - Medium
- September 15, 2021
Windows Key Storage Provider Security Feature Bypass Vulnerability
Sep 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-36975
7.8 - High
- September 15, 2021
Win32k Elevation of Privilege Vulnerability
Sep 2021: Windows SMB Elevation of Privilege Vulnerability
CVE-2021-36974
7.8 - High
- September 15, 2021
Windows SMB Elevation of Privilege Vulnerability
Sep 2021: Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
CVE-2021-36973
7.8 - High
- September 15, 2021
Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
Sep 2021: Windows SMB Information Disclosure Vulnerability
CVE-2021-36972
5.5 - Medium
- September 15, 2021
Windows SMB Information Disclosure Vulnerability
Sep 2021: Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-36969
5.5 - Medium
- September 15, 2021
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
Sep 2021: Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
CVE-2021-36967
8 - High
- September 15, 2021
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
Sep 2021: Windows Subsystem for Linux Elevation of Privilege Vulnerability
CVE-2021-36966
7.8 - High
- September 15, 2021
Windows Subsystem for Linux Elevation of Privilege Vulnerability
Sep 2021: Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
CVE-2021-36965
8.8 - High
- September 15, 2021
Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
Sep 2021: Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-36964
7.8 - High
- September 15, 2021
Windows Event Tracing Elevation of Privilege Vulnerability
Sep 2021: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36963
7.8 - High
- September 15, 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Sep 2021: Windows Installer Information Disclosure Vulnerability
CVE-2021-36962
5.5 - Medium
- September 15, 2021
Windows Installer Information Disclosure Vulnerability
Sep 2021: Windows Installer Denial of Service Vulnerability
CVE-2021-36961
5.5 - Medium
- September 15, 2021
Windows Installer Denial of Service Vulnerability
Sep 2021: Windows SMB Information Disclosure Vulnerability
CVE-2021-36960
7.5 - High
- September 15, 2021
Windows SMB Information Disclosure Vulnerability
Sep 2021: Windows Authenticode Spoofing Vulnerability
CVE-2021-36959
5.5 - Medium
- September 15, 2021
Windows Authenticode Spoofing Vulnerability
Sep 2021: Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2021-36954
8.8 - High
- September 15, 2021
Windows Bind Filter Driver Elevation of Privilege Vulnerability
Sep 2021: Windows Scripting Engine Memory Corruption Vulnerability
CVE-2021-26435
8.1 - High
- September 15, 2021
Windows Scripting Engine Memory Corruption Vulnerability
Sep 2021: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38638
7.8 - High
- September 15, 2021
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Improper Privilege Management
Sep 2021: Microsoft MSHTML Remote Code Execution Vulnerability
CVE-2021-40444
8.8 - High
- September 15, 2021
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: Suspicious Cpl File Execution. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.
Directory traversal
Sep 2021: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36955
7.8 - High
- September 15, 2021
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Aug 2021: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36926
7.5 - High
- August 12, 2021
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Aug 2021: Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2021-34537
7.8 - High
- August 12, 2021
Windows Bluetooth Driver Elevation of Privilege Vulnerability
Aug 2021: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36932
7.5 - High
- August 12, 2021
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Aug 2021: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36933
7.5 - High
- August 12, 2021
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
Aug 2021: Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-36947
8.8 - High
- August 12, 2021
Windows Print Spooler Remote Code Execution Vulnerability
Aug 2021: Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-36958
7.8 - High
- August 12, 2021
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Windows Server 2004 or by Microsoft? Click the Watch button to subscribe.