Vulnerabilities in microsoft
9,312 resultsVexday analysis
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2023-36591HIGHMicrosoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityEPSS 0.9%CVE-2021-26887HIGHMicrosoft Windows Folder Redirection Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2024-43518HIGHWindows Telephony Server Remote Code Execution VulnerabilityEPSS 0.9%CVE-2020-1333—An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group PolEPSS 0.9%CVE-2025-49657HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-47295HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-25185MEDIUMWindows Shell Link Processing Spoofing VulnerabilityEPSS 0.9%CVE-2026-56197HIGHWindows Admin Center (WAC) Remote Code Execution VulnerabilityEPSS 0.9%CVE-2020-1547HIGHWindows Backup Engine Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2021-42296HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.9%CVE-2020-1393—An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input,EPSS 0.9%CVE-2020-1336HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-21722MEDIUM.NET Framework Denial of Service VulnerabilityEPSS 0.9%CVE-2025-21365HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.9%CVE-2020-16887HIGHWindows Network Connections Service Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2022-24479HIGHConnected User Experiences and Telemetry Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2025-49717HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-35336MEDIUMWindows MSHTML Platform Security Feature Bypass VulnerabilityEPSS 0.9%CVE-2020-0647—A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications correctly, aka 'Microsoft Office EPSS 0.9%CVE-2020-17026HIGHWindows Remote Access Elevation of Privilege VulnerabilityEPSS 0.9%