Vulnerabilities in microsoft
9,312 resultsVexday analysis
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2023-28238HIGHWindows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution VulnerabilityEPSS 0.9%CVE-2020-0898—An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows GraphiEPSS 0.9%CVE-2024-49110MEDIUMWindows Mobile Broadband Driver Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2019-1433—An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows GraphiEPSS 0.9%CVE-2020-0834—An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker whoEPSS 0.9%CVE-2020-0819—An elevation of privilege vulnerability exists when the Windows Device Setup Manager improperly handles file operations, aka 'Windows DeviceEPSS 0.9%CVE-2020-0841—An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege VulEPSS 0.9%CVE-2020-0840—An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege VulEPSS 0.9%CVE-2020-0849—An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege VulEPSS 0.9%CVE-2020-1276—An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel ElevaEPSS 0.9%CVE-2023-35624HIGHAzure Connected Machine Agent Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-36886HIGHMicrosoft Dynamics 365 (on-premises) Cross-site Scripting VulnerabilityEPSS 0.9%CVE-2020-17076HIGHWindows Update Orchestrator Service Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2021-42280MEDIUMWindows Feedback Hub Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2020-16973HIGHWindows Backup Service Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2022-41103MEDIUMMicrosoft Word Information Disclosure VulnerabilityEPSS 0.9%CVE-2020-16909HIGHWindows Error Reporting Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2024-38245HIGHKernel Streaming Service Driver Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-21766MEDIUMWindows Overlay Filter Information Disclosure VulnerabilityEPSS 0.9%CVE-2023-28301LOWMicrosoft Edge (Chromium-based) Tampering VulnerabilityEPSS 0.9%