Microsoft Vulnerabilities and Affected Products
Vulnerabilities associated with Windows Server version 2004.
Products
Clear product- Windows Server 20194,131 vulnerabilities
- Windows Server 2019 (Server Core installation)4,034 vulnerabilities
- Windows 10 Version 18093,762 vulnerabilities
- Windows Server 20163,677 vulnerabilities
- Windows Server 20223,485 vulnerabilities
- Windows Server 2016 (Server Core installation)3,473 vulnerabilities
- Windows 10 Version 16073,184 vulnerabilities
- Windows 10 Version 21H23,063 vulnerabilities
- Windows Server 2012 R22,998 vulnerabilities
- Windows Server 2012 R2 (Server Core installation)2,853 vulnerabilities
- Windows Server 20122,824 vulnerabilities
- Windows Server 2012 (Server Core installation)2,691 vulnerabilities
- Windows 10 Version 22H22,565 vulnerabilities
- Windows 10 Version 15072,277 vulnerabilities
- Windows 11 Version 24H21,924 vulnerabilities
- Windows Server 20251,917 vulnerabilities
- Windows Server 2025 (Server Core installation)1,917 vulnerabilities
- Windows Server 2008 R2 Service Pack 11,874 vulnerabilities
- Windows Server 2008 R2 Service Pack 1 (Server Core installation)1,860 vulnerabilities
- Windows 11 Version 23H21,845 vulnerabilities
- Windows 11 version 22H21,776 vulnerabilities
- Windows Server 2022, 23H2 Edition (Server Core installation)1,725 vulnerabilities
- Windows Server 2008 Service Pack 2 (Server Core installation)1,667 vulnerabilities
- Windows Server 2008 Service Pack 21,664 vulnerabilities
- Windows 11 version 21H21,560 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-50508MEDIUM | Windows NTLM Spoofing VulnerabilityExposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. CWE-200Jun 9, 2026 | CVSS6.5v3.1 | EPSS8.68% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43893HIGH | Windows Encrypting File System (EFS) Elevation of Privilege VulnerabilityWindows Encrypting File System (EFS) Elevation of Privilege Vulnerability | CVSS7.5v3.1 | EPSS6.62% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43883HIGH | Windows Installer Elevation of Privilege VulnerabilityWindows Installer Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS12% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43248HIGH | Windows Digital Media Receiver Elevation of Privilege VulnerabilityWindows Digital Media Receiver Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43247HIGH | Windows TCP/IP Driver Elevation of Privilege VulnerabilityWindows TCP/IP Driver Elevation of Privilege Vulnerability | CVSS7.8v3.1 | EPSS0.901% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43246MEDIUM | Windows Hyper-V Denial of Service VulnerabilityWindows Hyper-V Denial of Service Vulnerability CWE-400Dec 15, 2021 | CVSS5.6v3.1 | EPSS0.75% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43244MEDIUM | Windows Kernel Information Disclosure VulnerabilityWindows Kernel Information Disclosure Vulnerability Dec 15, 2021 | CVSS6.5v3.1 | EPSS0.817% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43240HIGH | NTFS Set Short Name Elevation of Privilege VulnerabilityNTFS Set Short Name Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.557% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43239HIGH | Windows Recovery Environment Agent Elevation of Privilege VulnerabilityWindows Recovery Environment Agent Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.1v3.1 | EPSS0.544% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43238HIGH | Windows Remote Access Elevation of Privilege VulnerabilityWindows Remote Access Elevation of Privilege Vulnerability | CVSS7.8v3.1 | EPSS0.892% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43237HIGH | Windows Setup Elevation of Privilege VulnerabilityWindows Setup Elevation of Privilege Vulnerability | CVSS7.8v3.1 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43236HIGH | Microsoft Message Queuing Information Disclosure VulnerabilityMicrosoft Message Queuing Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43222. Dec 15, 2021 | CVSS7.5v3.1 | EPSS3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43235MEDIUM | Storage Spaces Controller Information Disclosure VulnerabilityStorage Spaces Controller Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43227. CWE-668Dec 15, 2021 | CVSS5.5v3.1 | EPSS0.769% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43234HIGH | Windows Fax Service Remote Code Execution VulnerabilityWindows Fax Service Remote Code Execution Vulnerability Dec 15, 2021 | CVSS7.8v3.1 | EPSS2.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43233HIGH | Remote Desktop Client Remote Code Execution VulnerabilityRemote Desktop Client Remote Code Execution Vulnerability CWE-94Dec 15, 2021 | CVSS7.5v3.1 | EPSS2.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43232HIGH | Windows Event Tracing Remote Code Execution VulnerabilityWindows Event Tracing Remote Code Execution Vulnerability CWE-94Dec 15, 2021 | CVSS7.8v3.1 | EPSS2.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43231HIGH | Windows NTFS Elevation of Privilege VulnerabilityWindows NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43229, CVE-2021-43230. CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.701% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43230HIGH | Windows NTFS Elevation of Privilege VulnerabilityWindows NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43229, CVE-2021-43231. CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.557% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43229HIGH | Windows NTFS Elevation of Privilege VulnerabilityWindows NTFS Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43230, CVE-2021-43231. CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS1.76% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43228HIGH | SymCrypt Denial of Service VulnerabilitySymCrypt Denial of Service Vulnerability CWE-400Dec 15, 2021 | CVSS7.5v3.1 | EPSS3.66% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43227MEDIUM | Storage Spaces Controller Information Disclosure VulnerabilityStorage Spaces Controller Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43235. CWE-668Dec 15, 2021 | CVSS5.5v3.1 | EPSS0.769% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43226HIGH | Windows Common Log File System Driver Elevation of Privilege VulnerabilityWindows Common Log File System Driver Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-43207. CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS3.07% | PoCs0 | SignalsListed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2021-43224MEDIUM | Windows Common Log File System Driver Information Disclosure VulnerabilityWindows Common Log File System Driver Information Disclosure Vulnerability CWE-668Dec 15, 2021 | CVSS5.5v3.1 | EPSS3.87% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43223HIGH | Windows Remote Access Connection Manager Elevation of Privilege VulnerabilityWindows Remote Access Connection Manager Elevation of Privilege Vulnerability CWE-269Dec 15, 2021 | CVSS7.8v3.1 | EPSS0.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-43222HIGH | Microsoft Message Queuing Information Disclosure VulnerabilityMicrosoft Message Queuing Information Disclosure Vulnerability This CVE ID is unique from CVE-2021-43236. CWE-668Dec 15, 2021 | CVSS7.5v3.1 | EPSS3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |