Exposure of Microsoft Excel

Editors
26
exposure score
134
sites use
1
exploited
0
critical
Vexday analysis

Com apenas 39 CVEs catalogadas, o Microsoft Excel apresenta volume relativamente contido de vulnerabilidades, mas sua taxa de exploração ativa está significativamente acima da média geral do catálogo — 5,7 vezes superior —, o que indica que as falhas historicamente identificadas nesta tecnologia tendem a ser aproveitadas na prática com frequência desproporcional. A CVE-2019-1297, a vulnerabilidade mais perigosa atualmente em exploração ativa, registra EPSS de 0,2046, sinalizando probabilidade não negligenciável de exploração observada em ambientes reais. O maior EPSS registrado entre as CVEs do produto chega a 0,28178, reforçando que ao menos parte do portfólio de vulnerabilidades continua relevante do ponto de vista operacional, mesmo sem registros de novas ocorrências nos últimos 90 dias. Equipes de segurança devem priorizar a verificação do status de correção das vulnerabilidades em KEV, dado o padrão histórico de exploração ativa acima da média.

CVEs

38 results
CVE-2019-1297HIGHA remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 21.8%KEVCVE-2019-1448—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 29.8%CVE-2018-8162—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 24.7%CVE-2018-8147—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 24.7%CVE-2018-8148—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 24.7%CVE-2018-0796—Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execuEPSS 23.3%CVE-2018-1029—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 20.8%CVE-2018-0920—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 20.6%CVE-2018-8502—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected VieEPSS 20.5%CVE-2018-1011—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 19.8%CVE-2019-1331—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 19.7%CVE-2018-8577—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 19.1%CVE-2018-8574—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 19.1%CVE-2018-1027—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 19.0%CVE-2020-0650—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 17.3%CVE-2020-0651—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 17.3%CVE-2020-1226—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 17.1%CVE-2020-1225—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 17.1%CVE-2018-8379—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 17.1%CVE-2018-8375—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 16.2%