VYPR

Windows Server 2003

by Microsoft

Source repositories

CVEs (5,318)

  • CVE-2019-0708CriKEVMay 16, 2019
    risk 0.93cvss 9.8epss 1.00

    A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution…

  • CVE-2025-59287CriKEVOct 14, 2025
    risk 0.87cvss 9.8epss 1.00

    Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.

  • CVE-2008-4250CriKEVOct 23, 2008
    risk 0.87cvss 9.8epss 0.99

    The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as…

  • CVE-2021-40444HigKEVSep 15, 2021
    risk 0.86cvss 8.8epss 0.97

    Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft…

  • CVE-2021-34527HigKEVJul 2, 2021
    risk 0.86cvss 8.8epss 1.00

    A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs;…

  • CVE-2020-1350CriKEVJul 14, 2020
    risk 0.84cvss 10.0epss 0.91

    A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.

  • CVE-2026-33824CriKEVApr 14, 2026
    risk 0.80cvss 9.8epss 0.78

    Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

  • CVE-2022-30190HigKEVJun 1, 2022
    risk 0.80cvss 7.8epss 0.99

    A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then…

  • CVE-2014-6332HigKEVNov 11, 2014
    risk 0.80cvss 8.8epss 0.95

    OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted…

  • CVE-2025-33053HigKEVJun 10, 2025
    risk 0.79cvss 8.8epss 0.85

    External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

  • CVE-2022-26923HigKEVMay 10, 2022
    risk 0.79cvss 8.8epss 0.83

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2014-6324HigKEVNov 18, 2014
    risk 0.79cvss 8.8epss 0.87

    The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain…

  • CVE-2024-21412HigKEVFeb 13, 2024
    risk 0.78cvss 8.1epss 0.95

    Internet Shortcut Files Security Feature Bypass Vulnerability

  • CVE-2021-40449HigKEVOct 13, 2021
    risk 0.78cvss 7.8epss 0.74

    Win32k Elevation of Privilege Vulnerability

  • CVE-2019-1458HigKEVDec 10, 2019
    risk 0.78cvss 7.8epss 0.74

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

  • CVE-2013-3918HigKEVNov 12, 2013
    risk 0.78cvss 8.8epss 0.74

    The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold…

  • CVE-2011-3402HigKEVNov 4, 2011
    risk 0.78cvss 8.8epss 0.78

    Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to…

  • CVE-2008-0015HigKEVJul 7, 2009
    risk 0.78cvss 8.8epss 0.77

    Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2,…

  • CVE-2025-33073HigKEVJun 10, 2025
    risk 0.77cvss 8.8epss 0.80

    Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

  • CVE-2018-8453HigKEVOct 10, 2018
    risk 0.77cvss 7.8epss 0.70

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…

Page 1 of 266