Vulnerabilities in Microsoft

10,811 results
Vexday analysis

Com 8.642 CVEs catalogadas e 248 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração do portfólio Microsoft está 6,4 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada em relação ao universo de vendors monitorados. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade com alto potencial de execução arbitrária de código e historicamente difícil de mitigar em escala. A CVE mais crítica atualmente em exploração ativa é CVE-2019-0708, com EPSS de 1,0 — o valor máximo da escala —, sinalizando probabilidade de exploração praticamente certa no curto prazo e exigindo atenção prioritária em ambientes onde a correção ainda não foi aplicada. Os 561 registros surgidos nos últimos 90 dias, combinados com 320 CVEs com prova de conceito pública, reforçam a necessidade de ciclos de patching contínuos e monitoramento ativo de exposição.

CVE-2025-21222HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.3%CVE-2025-21221HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.3%CVE-2025-21205HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.3%CVE-2020-1194—A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Registry Denial of SerEPSS 1.3%CVE-2022-24495HIGHWindows Direct Show Remote Code Execution VulnerabilityEPSS 1.3%CVE-2016-9486—On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because files are created in a folder with incorrect privilegesEPSS 1.3%CVE-2016-9485—On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because it fails to set any permissions on downloaded file objectsEPSS 1.3%CVE-2022-34707HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2019-0632—A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security FeaturEPSS 1.3%CVE-2019-0631—A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security FeaturEPSS 1.3%CVE-2024-20679MEDIUMAzure Stack Hub Spoofing VulnerabilityEPSS 1.3%CVE-2021-36959MEDIUMWindows Authenticode Spoofing VulnerabilityEPSS 1.3%CVE-2020-17135MEDIUMAzure DevOps Server Spoofing VulnerabilityEPSS 1.3%CVE-2025-21408HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-59864CRITICALKiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensionsEPSS 1.3%CVE-2025-29961MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.3%CVE-2025-29958MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.3%CVE-2020-1505MEDIUMMicrosoft SharePoint Information Disclosure VulnerabilityEPSS 1.3%CVE-2026-23666HIGH.NET Framework Denial of Service VulnerabilityEPSS 1.3%CVE-2020-1075MEDIUMWindows Subsystem for Linux Information Disclosure VulnerabilityEPSS 1.3%