Exposure of Windows Server

Operating systems
1,432
exposure score
228,411
sites use
32
exploited
3
critical
Vexday analysis

Windows Server acumula 831 CVEs catalogadas, das quais 33 estão confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 8,8 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada. A CVE mais perigosa em atividade, CVE-2019-0708, registra EPSS de 1,0, sinalizando probabilidade máxima de exploração e exigindo atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O tipo de falha mais recorrente é CWE-59 (improper link resolution before file access, ou "link following"), sugerindo que controles de integridade de sistema de arquivos e privilégios de acesso devem compor a linha de defesa prioritária. Embora nenhuma CVE nova tenha surgido nos últimos 90 dias, o perfil histórico da plataforma — com 3 falhas críticas ativas e EPSS máximo observado de 0,99999 — reforça a necessidade de gestão contínua e rigorosa de patches.

CVEs

755 results
CVE-2020-0612A denial of service vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an attacker connects to the target system usingEPSS 4.6%CVE-2020-1267This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attEPSS 4.5%CVE-2019-0865A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit thEPSS 4.5%CVE-2019-0811A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Windows DNS Server Denial EPSS 4.5%CVE-2020-0665An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trustEPSS 4.4%CVE-2020-1217An information disclosure vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime InformatiEPSS 4.4%CVE-2019-0731An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows ElevationEPSS 4.4%CVE-2019-0730An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows ElevationEPSS 4.4%CVE-2019-1365An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to itEPSS 4.4%CVE-2020-1317An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege VulnerabEPSS 4.3%CVE-2019-0836An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows ElevationEPSS 4.3%CVE-2019-0637A security feature bypass vulnerability exists when Windows Defender Firewall incorrectly applies firewall profiles to cellular network connEPSS 4.3%CVE-2019-0796An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows ElevationEPSS 4.2%CVE-2019-0734An elevation of privilege vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully decode and repEPSS 4.2%CVE-2020-0645A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server TamperingEPSS 3.9%CVE-2019-0732A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handlEPSS 3.8%CVE-2020-0728An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules InstaEPSS 3.7%CVE-2019-0735An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects inEPSS 3.7%CVE-2020-1309An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.To exploit this vulnerability, an EPSS 3.7%CVE-2019-1338A security feature bypass vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLEPSS 3.6%