Windows Nt
Vendor:
First CVE: Jan 1, 1995 · Active for 31 years
316
Total CVEs
More Total CVEs than 100% of tracked products
21.1
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Windows Nt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1995
31 years ago
Most Recent CVE
Apr 16, 2020
2,291 days ago
CVE Severity & Scoring
Windows Nt316 CVEs
41%
50%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (1.6%)
Network9 (2.8%)
Unknown302 (95.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (4.4%)
High0 (0.0%)
Unknown302 (95.6%)
User Interaction
None12 (3.8%)
Unknown302 (95.6%)
Required2 (0.6%)
Privileges Required
Low4 (1.3%)
High0 (0.0%)
None10 (3.2%)
Unknown302 (95.6%)
Top CVEs
Signals from CVEs in this product scope (316 CVEs).
316 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0352HIGH Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message | Aug 18, 2003 | 7.5 | 89 | NO | YES |
CVE-2003-0533HIGH Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, | Jun 1, 2004 | 7.5 | 84 | NO | YES |
CVE-2004-1080HIGH The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and poss | Jan 10, 2005 | 10.0 | 83 | NO | YES |
CVE-2003-0818HIGH Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP | Mar 3, 2004 | 7.5 | 83 | NO | YES |
CVE-2004-0206HIGH Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arb | Nov 3, 2004 | 7.5 | 81 | NO | YES |
CVE-2000-1089HIGH Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability. | Jan 9, 2001 | 10.0 | 81 | NO | YES |
CVE-1999-0874HIGH Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions. | Jun 16, 1999 | 10.0 | 81 | NO | YES |
CVE-2007-1070HIGH Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitr | Feb 21, 2007 | 10.0 | 80 | NO | YES |
CVE-2003-0719HIGH Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, | Jun 1, 2004 | 7.5 | 79 | NO | YES |
CVE-1999-0016MEDIUM Land IP denial of service. | Dec 1, 1997 | 5.0 | 79 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (316 CVEs).
CISA KEV
2 CVEs
0.6% of CVEs· 96th percentile
Metasploit
14 CVEs
4.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
99 CVEs
31.3% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (316 CVEs).
Media Mentions
Signals from CVEs in this product scope (316 CVEs).
Top CNAs Publishing CVEs For Windows Nt
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| xp_tablet_pc | 1 | 9.3 | 39.2% | 0 | 1 |
| xp | 9 | 8.9 | 34.2% | 0 | 3 |
| vista | 6 | 9.1 | 36.9% | 0 | 2 |
| terminal_server | 4 | 7.5 | 15.8% | 0 | 1 |
| datacenter_server | 1 | 9.3 | 39.2% | 0 | 1 |
| 4.0 | 193 | 6.9 | 29.0% | 2 | 71 |
| 3.5.1 | 12 | 6.7 | 12.3% | 0 | 3 |
| 3.51 | 1 | 2.1 | 2.0% | 0 | 0 |
| 2008 | 7 | 8.8 | 36.7% | 0 | 1 |
| 2003 | 1 | 5.0 | 70.0% | 0 | 1 |
| 2000 | 1 | 5.0 | 70.0% | 0 | 1 |