Windows Server 2004 Microsoft Windows Server 2004

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Windows Server 2004.

By the Year

In 2026 there have been 1 vulnerability in Microsoft Windows Server 2004 with an average score of 6.5 out of ten. Windows Server 2004 did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 6.50
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 218 7.42
2020 147 7.17

It may take a day or so for new Windows Server 2004 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Windows Server 2004 Security Vulnerabilities

Jun 2026: Windows NTLM Spoofing Vulnerability
CVE-2026-50508 6.5 - Medium - June 09, 2026

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

Information Disclosure

Dec 2021: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-43226 7.8 - High - December 15, 2021

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Nov 2021: Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42278 7.5 - High - November 10, 2021

Active Directory Domain Services Elevation of Privilege Vulnerability

Nov 2021: Windows Installer Elevation of Privilege Vulnerability
CVE-2021-41379 5.5 - Medium - November 10, 2021

Windows Installer Elevation of Privilege Vulnerability

insecure temporary file

Nov 2021: Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2021-42287 7.5 - High - November 10, 2021

Active Directory Domain Services Elevation of Privilege Vulnerability

Windows Nearby Sharing Elevation of Privilege Vulnerability
CVE-2021-40464 8 - High - October 13, 2021

Windows Nearby Sharing Elevation of Privilege Vulnerability

Improper Privilege Management

Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution Vulnerability
CVE-2021-40462 7.8 - High - October 13, 2021

Windows Media Foundation Dolby Digital Atmos Decoders Remote Code Execution Vulnerability

Windows Text Shaping Remote Code Execution Vulnerability
CVE-2021-40465 7.8 - High - October 13, 2021

Windows Text Shaping Remote Code Execution Vulnerability

Oct 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-41357 7.8 - High - October 13, 2021

Win32k Elevation of Privilege Vulnerability

Oct 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-40450 7.8 - High - October 13, 2021

Win32k Elevation of Privilege Vulnerability

Oct 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-40449 7.8 - High - October 13, 2021

Win32k Elevation of Privilege Vulnerability

Dangling pointer

Sep 2021: Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-40447 7.8 - High - September 15, 2021

Windows Print Spooler Elevation of Privilege Vulnerability

Sep 2021: Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38671 7.8 - High - September 15, 2021

Windows Print Spooler Elevation of Privilege Vulnerability

Sep 2021: Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2021-38667 7.8 - High - September 15, 2021

Windows Print Spooler Elevation of Privilege Vulnerability

Sep 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-38639 7.8 - High - September 15, 2021

Win32k Elevation of Privilege Vulnerability

Sep 2021: Windows Storage Information Disclosure Vulnerability
CVE-2021-38637 5.5 - Medium - September 15, 2021

Windows Storage Information Disclosure Vulnerability

Sep 2021: Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-38636 5.5 - Medium - September 15, 2021

Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability

Sep 2021: Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-38635 5.5 - Medium - September 15, 2021

Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability

Sep 2021: Microsoft Windows Update Client Elevation of Privilege Vulnerability
CVE-2021-38634 7.1 - High - September 15, 2021

Microsoft Windows Update Client Elevation of Privilege Vulnerability

Sep 2021: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-38633 7.8 - High - September 15, 2021

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Sep 2021: Windows BitLocker Security Feature Bypass Vulnerability
CVE-2021-38632 5.7 - Medium - September 15, 2021

Windows BitLocker Security Feature Bypass Vulnerability

Sep 2021: Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-38630 7.8 - High - September 15, 2021

Windows Event Tracing Elevation of Privilege Vulnerability

Sep 2021: Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability
CVE-2021-38629 6.5 - Medium - September 15, 2021

Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability

Sep 2021: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38628 7.8 - High - September 15, 2021

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Sep 2021: Windows Key Storage Provider Security Feature Bypass Vulnerability
CVE-2021-38624 6.5 - Medium - September 15, 2021

Windows Key Storage Provider Security Feature Bypass Vulnerability

Sep 2021: Win32k Elevation of Privilege Vulnerability
CVE-2021-36975 7.8 - High - September 15, 2021

Win32k Elevation of Privilege Vulnerability

Sep 2021: Windows SMB Elevation of Privilege Vulnerability
CVE-2021-36974 7.8 - High - September 15, 2021

Windows SMB Elevation of Privilege Vulnerability

Sep 2021: Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability
CVE-2021-36973 7.8 - High - September 15, 2021

Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability

Sep 2021: Windows SMB Information Disclosure Vulnerability
CVE-2021-36972 5.5 - Medium - September 15, 2021

Windows SMB Information Disclosure Vulnerability

Sep 2021: Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability
CVE-2021-36969 5.5 - Medium - September 15, 2021

Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability

Sep 2021: Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
CVE-2021-36967 8 - High - September 15, 2021

Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

Sep 2021: Windows Subsystem for Linux Elevation of Privilege Vulnerability
CVE-2021-36966 7.8 - High - September 15, 2021

Windows Subsystem for Linux Elevation of Privilege Vulnerability

Sep 2021: Windows WLAN AutoConfig Service Remote Code Execution Vulnerability
CVE-2021-36965 8.8 - High - September 15, 2021

Windows WLAN AutoConfig Service Remote Code Execution Vulnerability

Sep 2021: Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-36964 7.8 - High - September 15, 2021

Windows Event Tracing Elevation of Privilege Vulnerability

Sep 2021: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36963 7.8 - High - September 15, 2021

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Sep 2021: Windows Installer Information Disclosure Vulnerability
CVE-2021-36962 5.5 - Medium - September 15, 2021

Windows Installer Information Disclosure Vulnerability

Sep 2021: Windows Installer Denial of Service Vulnerability
CVE-2021-36961 5.5 - Medium - September 15, 2021

Windows Installer Denial of Service Vulnerability

Sep 2021: Windows SMB Information Disclosure Vulnerability
CVE-2021-36960 7.5 - High - September 15, 2021

Windows SMB Information Disclosure Vulnerability

Sep 2021: Windows Authenticode Spoofing Vulnerability
CVE-2021-36959 5.5 - Medium - September 15, 2021

Windows Authenticode Spoofing Vulnerability

Sep 2021: Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2021-36954 8.8 - High - September 15, 2021

Windows Bind Filter Driver Elevation of Privilege Vulnerability

Sep 2021: Windows Scripting Engine Memory Corruption Vulnerability
CVE-2021-26435 8.1 - High - September 15, 2021

Windows Scripting Engine Memory Corruption Vulnerability

Sep 2021: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2021-38638 7.8 - High - September 15, 2021

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Improper Privilege Management

Sep 2021: Microsoft MSHTML Remote Code Execution Vulnerability
CVE-2021-40444 8.8 - High - September 15, 2021

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: Suspicious Cpl File Execution. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.

Directory traversal

Sep 2021: Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2021-36955 7.8 - High - September 15, 2021

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Aug 2021: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36926 7.5 - High - August 12, 2021

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

Aug 2021: Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2021-34537 7.8 - High - August 12, 2021

Windows Bluetooth Driver Elevation of Privilege Vulnerability

Aug 2021: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36932 7.5 - High - August 12, 2021

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

Aug 2021: Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2021-36933 7.5 - High - August 12, 2021

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

Aug 2021: Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-36947 8.8 - High - August 12, 2021

Windows Print Spooler Remote Code Execution Vulnerability

Aug 2021: Windows Print Spooler Remote Code Execution Vulnerability
CVE-2021-36958 7.8 - High - August 12, 2021

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Windows Server 2004 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe