Windows Server 2003
Vendor:
First CVE: Nov 17, 2003 · Active for 22 years
654
Total CVEs
More Total CVEs than 100% of tracked products
43.6
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
5.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Windows Server 2003 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2003
22 years ago
Most Recent CVE
Feb 20, 2020
2,346 days ago
CVE Severity & Scoring
Windows Server 2003654 CVEs
20%
76%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local41 (6.3%)
Network68 (10.4%)
Unknown545 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low86 (13.1%)
High23 (3.5%)
Unknown545 (83.3%)
User Interaction
None62 (9.5%)
Unknown545 (83.3%)
Required47 (7.2%)
Privileges Required
Low19 (2.9%)
High0 (0.0%)
None90 (13.8%)
Unknown545 (83.3%)
Top CVEs
Signals from CVEs in this product scope (654 CVEs).
654 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7269CRITICAL Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to | Mar 27, 2017 | 9.8 | 99 | YES | YES |
CVE-2013-2251CRITICAL Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: p | Jul 20, 2013 | 9.8 | 99 | YES | YES |
CVE-2014-6332HIGH OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and | Nov 11, 2014 | 8.8 | 98 | YES | YES |
CVE-2010-3962HIGH Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token | Nov 5, 2010 | 8.1 | 98 | YES | YES |
CVE-2010-0249HIGH Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP | Jan 15, 2010 | 8.8 | 98 | YES | YES |
CVE-2008-4250CRITICAL The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitr | Oct 23, 2008 | 9.8 | 98 | YES | YES |
CVE-2014-6324HIGH The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and W | Nov 18, 2014 | 8.8 | 97 | YES | YES |
CVE-2014-4113HIGH win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Se | Oct 15, 2014 | 7.8 | 97 | YES | YES |
CVE-2012-4792HIGH Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object t | Dec 30, 2012 | 8.8 | 97 | YES | YES |
CVE-2012-4969HIGH Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafte | Sep 18, 2012 | 8.1 | 97 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (654 CVEs).
CISA KEV
34 CVEs
5.2% of CVEs· 97th percentile
Metasploit
52 CVEs
8.0% of CVEs· 97th percentile
Nuclei
2 CVEs
0.3% of CVEs· 96th percentile
ExploitDB
137 CVEs
20.9% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (654 CVEs).
Media Mentions
Signals from CVEs in this product scope (654 CVEs).
Top CNAs Publishing CVEs For Windows Server 2003
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| web_edition_sp1 | 1 | 9.3 | 39.2% | 0 | 1 |
| standard_sp1 | 1 | 9.3 | 39.2% | 0 | 1 |
| sp1 | 1 | 7.5 | 44.5% | 0 | 0 |
| r2 | 16 | 7.3 | 12.2% | 1 | 8 |
| enterprise_sp1 | 1 | 9.3 | 39.2% | 0 | 1 |
| datacenter_sp1 | 1 | 9.3 | 39.2% | 0 | 1 |