Windows Server 2003
by Microsoft
Source repositories
CVEs (5,318)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23392 | Cri | 0.64 | 9.8 | 0.02 | Mar 14, 2023 | HTTP Protocol Stack Remote Code Execution Vulnerability | ||
| CVE-2023-21708 | Cri | 0.64 | 9.8 | 0.01 | Mar 14, 2023 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2022-38028 | Hig | 0.64 | 7.8 | 0.15 | KEV | Oct 11, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2022-34722 | Cri | 0.64 | 9.8 | 0.02 | Sep 13, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-30133 | Cri | 0.64 | 9.8 | 0.03 | Aug 9, 2022 | Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | ||
| CVE-2022-30216 | Hig | 0.64 | 8.8 | 0.89 | Jul 12, 2022 | Windows Server Service Tampering Vulnerability | ||
| CVE-2022-22047 | Hig | 0.64 | 7.8 | 0.17 | KEV | Jul 12, 2022 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | |
| CVE-2022-29130 | Cri | 0.64 | 9.8 | 0.04 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-22012 | Cri | 0.64 | 9.8 | 0.04 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-22718 | Hig | 0.64 | 7.8 | 0.18 | KEV | Feb 9, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | |
| CVE-2022-21849 | Cri | 0.64 | 9.8 | 0.06 | Jan 11, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2021-43215 | Cri | 0.64 | 9.8 | 0.03 | Dec 15, 2021 | iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution | ||
| CVE-2020-0986 | Hig | 0.64 | 7.8 | 0.16 | KEV | Jun 9, 2020 | An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266,… | |
| CVE-2020-0690 | Cri | 0.64 | 9.8 | 0.07 | Mar 12, 2020 | An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. | ||
| CVE-2019-0786 | Cri | 0.64 | 9.8 | 0.07 | Apr 9, 2019 | An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privilege Vulnerability'. | ||
| CVE-2018-8544 | Hig | 0.64 | 8.8 | 0.41 | Nov 14, 2018 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server… | ||
| CVE-2026-21533 | Hig | 0.63 | 7.8 | 0.04 | KEV | Feb 10, 2026 | Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-21519 | Hig | 0.63 | 7.8 | 0.02 | KEV | Feb 10, 2026 | Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-62221 | Hig | 0.63 | 7.8 | 0.02 | KEV | Dec 9, 2025 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-59230 | Hig | 0.63 | 7.8 | 0.03 | KEV | Oct 14, 2025 | Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. |
- risk 0.64cvss 9.8epss 0.02
HTTP Protocol Stack Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.01
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.64cvss 7.8epss 0.15
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.02
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
- risk 0.64cvss 8.8epss 0.89
Windows Server Service Tampering Vulnerability
- risk 0.64cvss 7.8epss 0.17
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.04
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.04
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.64cvss 7.8epss 0.18
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.64cvss 9.8epss 0.06
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.64cvss 9.8epss 0.03
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
- risk 0.64cvss 7.8epss 0.16
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266,…
- risk 0.64cvss 9.8epss 0.07
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
- risk 0.64cvss 9.8epss 0.07
An elevation of privilege vulnerability exists in the Microsoft Server Message Block (SMB) Server when an attacker with valid credentials attempts to open a specially crafted file over the SMB protocol on the same machine, aka 'SMB Server Elevation of Privilege Vulnerability'.
- risk 0.64cvss 8.8epss 0.41
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server…
- risk 0.63cvss 7.8epss 0.04
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
- risk 0.63cvss 7.8epss 0.02
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- risk 0.63cvss 7.8epss 0.02
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- risk 0.63cvss 7.8epss 0.03
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Page 10 of 266