Windows 2003 Server
Vendor:
First CVE: Dec 31, 2002 · Active for 23 years
545
Total CVEs
More Total CVEs than 100% of tracked products
38.9
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.7%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Windows 2003 Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Jul 14, 2015
4,028 days ago
CVE Severity & Scoring
Windows 2003 Server545 CVEs
24%
72%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local20 (3.7%)
Network22 (4.0%)
Unknown503 (92.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (6.1%)
High9 (1.7%)
Unknown503 (92.3%)
User Interaction
None27 (5.0%)
Unknown503 (92.3%)
Required15 (2.8%)
Privileges Required
Low10 (1.8%)
High0 (0.0%)
None32 (5.9%)
Unknown503 (92.3%)
Top CVEs
Signals from CVEs in this product scope (545 CVEs).
545 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0015HIGH Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in Dir | Jul 7, 2009 | 8.8 | 97 | YES | YES |
CVE-2015-1701HIGH Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as explo | Apr 21, 2015 | 7.8 | 93 | YES | YES |
CVE-2013-5065HIGH NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in Novem | Nov 28, 2013 | 7.8 | 90 | YES | YES |
CVE-2003-0352HIGH Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message | Aug 18, 2003 | 7.5 | 89 | NO | YES |
CVE-2009-1537HIGH Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Wi | May 29, 2009 | 8.8 | 87 | YES | NO |
CVE-2010-2550HIGH The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly valid | Aug 11, 2010 | 10.0 | 86 | NO | YES |
CVE-2006-3439HIGH Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary co | Aug 9, 2006 | 10.0 | 86 | NO | YES |
CVE-2010-0483HIGH vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote atta | Mar 3, 2010 | 7.6 | 85 | NO | YES |
CVE-2011-0654HIGH Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Wi | Feb 16, 2011 | 10.0 | 84 | NO | YES |
CVE-2010-1885HIGH The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, wh | Jun 15, 2010 | 9.3 | 84 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (545 CVEs).
CISA KEV
4 CVEs
0.7% of CVEs· 96th percentile
Metasploit
33 CVEs
6.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
144 CVEs
26.4% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (545 CVEs).
Media Mentions
Signals from CVEs in this product scope (545 CVEs).
Top CNAs Publishing CVEs For Windows 2003 Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| xp_sp2 | 2 | 9.7 | 45.0% | 0 | 0 |
| web_edition | 1 | 9.3 | 39.2% | 0 | 1 |
| web | 66 | 6.9 | 30.6% | 0 | 26 |
| standard_64-bit | 22 | 6.8 | 34.2% | 0 | 10 |
| standard | 67 | 7.0 | 30.4% | 0 | 27 |
| sp2 | 19 | 8.1 | 28.2% | 0 | 5 |
| sp1 | 51 | 7.3 | 36.6% | 0 | 23 |
| r2 | 136 | 6.8 | 32.5% | 1 | 53 |
| professional | 2 | 7.5 | 17.5% | 0 | 2 |
| mobile_pocket_pc | 1 | 10.0 | 13.4% | 0 | 0 |
| itanium | 15 | 7.3 | 40.8% | 0 | 9 |
| gold | 8 | 7.3 | 24.3% | 0 | 4 |
| enterprise_edition_itanium | 1 | 4.3 | 23.2% | 0 | 1 |
| enterprise_edition_64-bit | 7 | 6.8 | 30.7% | 0 | 3 |
| enterprise_edition | 9 | 6.3 | 24.0% | 0 | 5 |
| enterprise_64-bit | 57 | 7.1 | 31.9% | 0 | 22 |
| enterprise | 59 | 7.1 | 30.7% | 0 | 22 |
| datacenter_server | 1 | 7.5 | 20.2% | 0 | 1 |
| datacenter_edition_itanium | 1 | 4.3 | 23.2% | 0 | 1 |
| datacenter_edition_64-bit | 7 | 6.6 | 30.2% | 0 | 3 |