Windows Vista

Vendor:

First CVE: Dec 22, 2006 · Active for 19 years

1,348
Total CVEs
More Total CVEs than 100% of tracked products
96.3
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
5.0%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Windows Vista over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 22, 2006
19 years ago
Most Recent CVE
Feb 20, 2020
2,347 days ago

CVE Severity & Scoring

Windows Vista1,348 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local171 (12.7%)
Network160 (11.9%)
Unknown1,007 (74.7%)
Physical2 (0.1%)
Adjacent Network8 (0.6%)
Attack Complexity
Low288 (21.4%)
High53 (3.9%)
Unknown1,007 (74.7%)
User Interaction
None160 (11.9%)
Unknown1,007 (74.7%)
Required181 (13.4%)
Privileges Required
Low103 (7.6%)
High7 (0.5%)
None231 (17.1%)
Unknown1,007 (74.7%)

Top CVEs

Signals from CVEs in this product scope (1348 CVEs).

1,348 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows
Apr 12, 20177.898YESYES
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gol
Mar 17, 20178.198YESYES
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gol
Mar 17, 20177.598YESYES
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gol
Mar 17, 20178.898YESYES
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gol
Mar 17, 20178.898YESYES
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and
Nov 11, 20148.898YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token
Nov 5, 20108.198YESYES
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP
Jan 15, 20108.898YESYES
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitr
Oct 23, 20089.898YESYES
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gol
Mar 17, 20178.897YESYES

Exploit Exposure

Signals from CVEs in this product scope (1348 CVEs).

CISA KEV
67 CVEs
5.0% of CVEs· 97th percentile
Metasploit
82 CVEs
6.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
300 CVEs
22.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (1348 CVEs).

Media Mentions

Signals from CVEs in this product scope (1348 CVEs).

Top CNAs Publishing CVEs For Windows Vista

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
sp236.42.7%01
sp177.414.3%02
gold148.114.2%03