Windows Server

Vendor:

First CVE: Jun 19, 2006 · Active for 20 years

303
Total CVEs
More Total CVEs than 100% of tracked products
33.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Windows Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2006
20 years ago
Most Recent CVE
May 10, 2022
1,536 days ago

CVE Severity & Scoring

Windows Server303 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local177 (58.4%)
Network100 (33.0%)
Unknown9 (3.0%)
Physical9 (3.0%)
Adjacent Network8 (2.6%)
Attack Complexity
Low213 (70.3%)
High81 (26.7%)
Unknown9 (3.0%)
User Interaction
None239 (78.9%)
Unknown9 (3.0%)
Required55 (18.2%)
Privileges Required
Low188 (62.0%)
High6 (2.0%)
None100 (33.0%)
Unknown9 (3.0%)

Top CVEs

Signals from CVEs in this product scope (303 CVEs).

303 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HTTP Protocol Stack Remote Code Execution Vulnerability
Jan 11, 20229.887NOYES
Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how
Nov 15, 20177.571NOYES
Windows Network File System Remote Code Execution Vulnerability
May 10, 20229.870NONO
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
May 10, 20228.170NONO
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripti
Nov 15, 20177.568NOYES
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the curr
Nov 15, 20177.567NOYES
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
May 10, 20228.162NONO
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects
Sep 13, 20188.855NONO
Windows DCOM Server Security Feature Bypass
Jun 8, 20216.551NONO
Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability
Mar 9, 20226.550NONO

Exploit Exposure

Signals from CVEs in this product scope (303 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
5.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (303 CVEs).

Media Mentions

Signals from CVEs in this product scope (303 CVEs).

Top CNAs Publishing CVEs For Windows Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
20h22047.34.0%01
20221697.33.9%01
201657.716.5%01
201277.714.6%01
200878.021.4%01
200426.025.2%00
200319.330.5%00
180357.44.9%00
1709335.84.0%09