Vulnerabilities in microsoft
9,312 resultsVexday analysis
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2026-56647HIGHWindows Remote Access Service Infrastructure Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2020-1014—An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'MicrEPSS 0.9%CVE-2021-1695HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-45584HIGHMicrosoft Defender Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-56194HIGHWindows NFS Server Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-36728MEDIUMMicrosoft SQL Server Denial of Service VulnerabilityEPSS 0.9%CVE-2025-50168HIGHWin32k Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2025-21226MEDIUMWindows Digital Media Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2021-31937HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2020-0750—An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'ConnecEPSS 0.8%CVE-2024-38102MEDIUMWindows Layer-2 Bridge Network Driver Denial of Service VulnerabilityEPSS 0.8%CVE-2021-33760MEDIUMMedia Foundation Information Disclosure VulnerabilityEPSS 0.8%CVE-2020-0749—An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'ConnecEPSS 0.8%CVE-2020-0613—An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search IndEPSS 0.8%CVE-2020-0680—An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'WindowEPSS 0.8%CVE-2024-21384HIGHMicrosoft Office OneNote Remote Code Execution VulnerabilityEPSS 0.8%CVE-2020-0659—An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data SEPSS 0.8%CVE-2020-0657—An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aEPSS 0.8%CVE-2026-56159CRITICALDHCP Server Service Remote Code Execution VulnerabilityEPSS 0.8%CVE-2020-0666—An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search IndEPSS 0.8%