Windows Server 2003

Vendor:

First CVE: Nov 17, 2003 · Active for 22 years

654
Total CVEs
More Total CVEs than 100% of tracked products
43.6
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
5.2%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Windows Server 2003 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2003
22 years ago
Most Recent CVE
Feb 20, 2020
2,346 days ago

CVE Severity & Scoring

Windows Server 2003654 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local41 (6.3%)
Network68 (10.4%)
Unknown545 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low86 (13.1%)
High23 (3.5%)
Unknown545 (83.3%)
User Interaction
None62 (9.5%)
Unknown545 (83.3%)
Required47 (7.2%)
Privileges Required
Low19 (2.9%)
High0 (0.0%)
None90 (13.8%)
Unknown545 (83.3%)

Top CVEs

Signals from CVEs in this product scope (654 CVEs).

654 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to
Mar 27, 20179.899YESYES
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: p
Jul 20, 20139.899YESYES
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and
Nov 11, 20148.898YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token
Nov 5, 20108.198YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP
Jan 15, 20108.898YESYES
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitr
Oct 23, 20089.898YESYES
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and W
Nov 18, 20148.897YESYES
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Se
Oct 15, 20147.897YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object t
Dec 30, 20128.897YESYES
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafte
Sep 18, 20128.197YESYES

Exploit Exposure

Signals from CVEs in this product scope (654 CVEs).

CISA KEV
34 CVEs
5.2% of CVEs· 97th percentile
Metasploit
52 CVEs
8.0% of CVEs· 97th percentile
Nuclei
2 CVEs
0.3% of CVEs· 96th percentile
ExploitDB
137 CVEs
20.9% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (654 CVEs).

Media Mentions

Signals from CVEs in this product scope (654 CVEs).

Top CNAs Publishing CVEs For Windows Server 2003

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
web_edition_sp119.339.2%01
standard_sp119.339.2%01
sp117.544.5%00
r2167.312.2%18
enterprise_sp119.339.2%01
datacenter_sp119.339.2%01