Vulnerabilities in Microsoft

9,326 results
Vexday analysis

Com 8.642 CVEs catalogadas e 248 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração do portfólio Microsoft está 6,4 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada em relação ao universo de vendors monitorados. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade com alto potencial de execução arbitrária de código e historicamente difícil de mitigar em escala. A CVE mais crítica atualmente em exploração ativa é CVE-2019-0708, com EPSS de 1,0 — o valor máximo da escala —, sinalizando probabilidade de exploração praticamente certa no curto prazo e exigindo atenção prioritária em ambientes onde a correção ainda não foi aplicada. Os 561 registros surgidos nos últimos 90 dias, combinados com 320 CVEs com prova de conceito pública, reforçam a necessidade de ciclos de patching contínuos e monitoramento ativo de exposição.

CVE-2021-26418MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.2%CVE-2023-32056HIGHWindows Server Update Service (WSUS) Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2024-21448MEDIUMMicrosoft Teams for Android Information Disclosure VulnerabilityEPSS 1.2%CVE-2022-30200HIGHWindows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityEPSS 1.2%CVE-2020-17020LOWMicrosoft Word Security Feature Bypass VulnerabilityEPSS 1.2%CVE-2023-36722MEDIUMActive Directory Domain Services Information Disclosure VulnerabilityEPSS 1.2%CVE-2019-0775An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel InformationEPSS 1.2%CVE-2023-32038HIGHMicrosoft ODBC Driver Remote Code Execution VulnerabilityEPSS 1.2%CVE-2020-0904MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 1.2%CVE-2020-0886HIGHWindows Storage Services Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2020-1070An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file systemEPSS 1.2%CVE-2021-38652HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.2%CVE-2016-9485On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because it fails to set any permissions on downloaded file objectsEPSS 1.2%CVE-2016-9486On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because files are created in a folder with incorrect privilegesEPSS 1.2%CVE-2021-38651HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.2%CVE-2025-29804HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2022-37956HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2024-21326CRITICALMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2020-17135MEDIUMAzure DevOps Server Spoofing VulnerabilityEPSS 1.2%CVE-2019-1391A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. TEPSS 1.2%