Project Server
Vendor:
First CVE: Dec 18, 2006 · Active for 19 years
24
Total CVEs
More Total CVEs than 95% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Project Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2006
19 years ago
Most Recent CVE
Apr 15, 2020
2,291 days ago
CVE Severity & Scoring
Project Server24 CVEs
38%
63%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (4.2%)
Network18 (75.0%)
Unknown5 (20.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (75.0%)
High1 (4.2%)
Unknown5 (20.8%)
User Interaction
None10 (41.7%)
Unknown5 (20.8%)
Required9 (37.5%)
Privileges Required
Low15 (62.5%)
High0 (0.0%)
None4 (16.7%)
Unknown5 (20.8%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8284HIGH A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affe | Jul 11, 2018 | 8.1 | 48 | NO | NO |
CVE-2009-0102HIGH Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitra | Dec 9, 2009 | 9.3 | 34 | NO | NO |
CVE-2017-0281HIGH Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, Sha | May 12, 2017 | 7.8 | 33 | NO | NO |
CVE-2015-2503HIGH Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 200 | Nov 11, 2015 | 9.3 | 30 | NO | NO |
CVE-2018-0915HIGH Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are saniti | Mar 14, 2018 | 8.8 | 29 | NO | NO |
CVE-2017-11876HIGH Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the v | Nov 15, 2017 | 8.8 | 29 | NO | NO |
CVE-2018-0912HIGH Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are saniti | Mar 14, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-0909HIGH Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are saniti | Mar 14, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-0914HIGH Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are saniti | Mar 14, 2018 | 8.8 | 27 | NO | NO |
CVE-2014-0251HIGH Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1; Pr | May 14, 2014 | 9.0 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Project Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2013 | 18 | 8.0 | 8.3% | 0 | 0 |
| 2010 | 9 | 6.7 | 10.1% | 0 | 0 |
| 2007 | 1 | 9.3 | 23.5% | 0 | 0 |
| 2003 | 2 | 7.9 | 21.9% | 0 | 0 |