Windows Server
Vendor:
First CVE: Jun 19, 2006 · Active for 20 years
303
Total CVEs
More Total CVEs than 100% of tracked products
33.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Windows Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2006
20 years ago
Most Recent CVE
May 10, 2022
1,536 days ago
CVE Severity & Scoring
Windows Server303 CVEs
31%
64%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local177 (58.4%)
Network100 (33.0%)
Unknown9 (3.0%)
Physical9 (3.0%)
Adjacent Network8 (2.6%)
Attack Complexity
Low213 (70.3%)
High81 (26.7%)
Unknown9 (3.0%)
User Interaction
None239 (78.9%)
Unknown9 (3.0%)
Required55 (18.2%)
Privileges Required
Low188 (62.0%)
High6 (2.0%)
None100 (33.0%)
Unknown9 (3.0%)
Top CVEs
Signals from CVEs in this product scope (303 CVEs).
303 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21907CRITICAL HTTP Protocol Stack Remote Code Execution Vulnerability | Jan 11, 2022 | 9.8 | 87 | NO | YES |
CVE-2017-11861HIGH Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how | Nov 15, 2017 | 7.5 | 71 | NO | YES |
CVE-2022-26937CRITICAL Windows Network File System Remote Code Execution Vulnerability | May 10, 2022 | 9.8 | 70 | NO | NO |
CVE-2022-21972HIGH Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | May 10, 2022 | 8.1 | 70 | NO | NO |
CVE-2017-11870HIGH ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripti | Nov 15, 2017 | 7.5 | 68 | NO | YES |
CVE-2017-11873HIGH ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the curr | Nov 15, 2017 | 7.5 | 67 | NO | YES |
CVE-2022-23270HIGH Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | May 10, 2022 | 8.1 | 62 | NO | NO |
CVE-2018-8420HIGH A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects | Sep 13, 2018 | 8.8 | 55 | NO | NO |
CVE-2021-26414MEDIUM Windows DCOM Server Security Feature Bypass | Jun 8, 2021 | 6.5 | 51 | NO | NO |
CVE-2022-23253MEDIUM Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | Mar 9, 2022 | 6.5 | 50 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (303 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
5.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (303 CVEs).
Media Mentions
Signals from CVEs in this product scope (303 CVEs).
Top CNAs Publishing CVEs For Windows Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 20h2 | 204 | 7.3 | 4.0% | 0 | 1 |
| 2022 | 169 | 7.3 | 3.9% | 0 | 1 |
| 2016 | 5 | 7.7 | 16.5% | 0 | 1 |
| 2012 | 7 | 7.7 | 14.6% | 0 | 1 |
| 2008 | 7 | 8.0 | 21.4% | 0 | 1 |
| 2004 | 2 | 6.0 | 25.2% | 0 | 0 |
| 2003 | 1 | 9.3 | 30.5% | 0 | 0 |
| 1803 | 5 | 7.4 | 4.9% | 0 | 0 |
| 1709 | 33 | 5.8 | 4.0% | 0 | 9 |