Windows 2003 Server

Vendor:

First CVE: Dec 31, 2002 · Active for 23 years

545
Total CVEs
More Total CVEs than 100% of tracked products
38.9
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.7%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Windows 2003 Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Jul 14, 2015
4,028 days ago

CVE Severity & Scoring

Windows 2003 Server545 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local20 (3.7%)
Network22 (4.0%)
Unknown503 (92.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (6.1%)
High9 (1.7%)
Unknown503 (92.3%)
User Interaction
None27 (5.0%)
Unknown503 (92.3%)
Required15 (2.8%)
Privileges Required
Low10 (1.8%)
High0 (0.0%)
None32 (5.9%)
Unknown503 (92.3%)

Top CVEs

Signals from CVEs in this product scope (545 CVEs).

545 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in Dir
Jul 7, 20098.897YESYES
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as explo
Apr 21, 20157.893YESYES
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in Novem
Nov 28, 20137.890YESYES
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message
Aug 18, 20037.589NOYES
Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Wi
May 29, 20098.887YESNO
The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly valid
Aug 11, 201010.086NOYES
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary co
Aug 9, 200610.086NOYES
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote atta
Mar 3, 20107.685NOYES
Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Wi
Feb 16, 201110.084NOYES
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, wh
Jun 15, 20109.384NOYES

Exploit Exposure

Signals from CVEs in this product scope (545 CVEs).

CISA KEV
4 CVEs
0.7% of CVEs· 96th percentile
Metasploit
33 CVEs
6.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
144 CVEs
26.4% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (545 CVEs).

Media Mentions

Signals from CVEs in this product scope (545 CVEs).

Top CNAs Publishing CVEs For Windows 2003 Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
xp_sp229.745.0%00
web_edition19.339.2%01
web666.930.6%026
standard_64-bit226.834.2%010
standard677.030.4%027
sp2198.128.2%05
sp1517.336.6%023
r21366.832.5%153
professional27.517.5%02
mobile_pocket_pc110.013.4%00
itanium157.340.8%09
gold87.324.3%04
enterprise_edition_itanium14.323.2%01
enterprise_edition_64-bit76.830.7%03
enterprise_edition96.324.0%05
enterprise_64-bit577.131.9%022
enterprise597.130.7%022
datacenter_server17.520.2%01
datacenter_edition_itanium14.323.2%01
datacenter_edition_64-bit76.630.2%03