Exposure of Windows Server

Operating systems
1,432
exposure score
228,411
sites use
32
exploited
3
critical
Vexday analysis

Windows Server acumula 831 CVEs catalogadas, das quais 33 estão confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 8,8 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada. A CVE mais perigosa em atividade, CVE-2019-0708, registra EPSS de 1,0, sinalizando probabilidade máxima de exploração e exigindo atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O tipo de falha mais recorrente é CWE-59 (improper link resolution before file access, ou "link following"), sugerindo que controles de integridade de sistema de arquivos e privilégios de acesso devem compor a linha de defesa prioritária. Embora nenhuma CVE nova tenha surgido nos últimos 90 dias, o perfil histórico da plataforma — com 3 falhas críticas ativas e EPSS máximo observado de 0,99999 — reforça a necessidade de gestão contínua e rigorosa de patches.

CVEs

755 results
CVE-2020-0744An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowiEPSS 1.9%CVE-2019-0601An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HEPSS 1.8%CVE-2019-0975A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addEPSS 1.8%CVE-2019-0767An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerabilitEPSS 1.8%CVE-2019-1436An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information DisEPSS 1.8%CVE-2019-1483An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerabEPSS 1.8%CVE-2019-1418An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules InstaEPSS 1.7%CVE-2019-1097An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite InformatioEPSS 1.7%CVE-2019-1093An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite InformatioEPSS 1.7%CVE-2019-0759An information disclosure vulnerability exists when the Windows Print Spooler does not properly handle objects in memory, aka 'Windows PrintEPSS 1.7%CVE-2019-0886An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authEPSS 1.7%CVE-2019-0928A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on EPSS 1.7%CVE-2019-1399A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on EPSS 1.7%CVE-2019-0600An information disclosure vulnerability exists when the Human Interface Devices (HID) component improperly handles objects in memory, aka 'HEPSS 1.7%CVE-2019-1412An information disclosure vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objectEPSS 1.7%CVE-2019-1251An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite InformatioEPSS 1.7%CVE-2019-1219An information disclosure vulnerability exists when the Windows Transaction Manager improperly handles objects in memory, aka 'Windows TransEPSS 1.7%CVE-2019-1216An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Information Disclosure VulnerEPSS 1.7%CVE-2020-0987An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'MicrEPSS 1.7%CVE-2020-0615An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects EPSS 1.7%