Vulnerabilities in microsoft

9,312 results
Vexday analysis

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2024-38119HIGHWindows Network Address Translation (NAT) Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-38034HIGHWindows Filtering Platform Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-55010CRITICALMinecraft Bedrock Dedicated Server Remote Code Execution VulnerabilityEPSS 0.8%CVE-2020-1306An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime ElevationEPSS 0.8%CVE-2020-0631An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search IndEPSS 0.8%CVE-2024-38057HIGHKernel Streaming WOW Thunk Service Driver Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2020-0868An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'WindowsEPSS 0.8%CVE-2020-0857An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search IndEPSS 0.8%CVE-2021-1727HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-41051HIGHAzure RTOS GUIX Studio Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-28902MEDIUMWindows Remote Access Connection Manager Information Disclosure VulnerabilityEPSS 0.8%CVE-2022-40732MEDIUMAn access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of WindEPSS 0.8%CVE-2024-26207MEDIUMWindows Remote Access Connection Manager Information Disclosure VulnerabilityEPSS 0.8%CVE-2026-50366MEDIUMWindows Active Directory Domain Services Denial of Service VulnerabilityEPSS 0.8%CVE-2024-26255MEDIUMWindows Remote Access Connection Manager Information Disclosure VulnerabilityEPSS 0.8%CVE-2026-57976MEDIUMWindows Active Directory Domain Services Denial of Service VulnerabilityEPSS 0.8%CVE-2023-36398MEDIUMWindows NTFS Information Disclosure VulnerabilityEPSS 0.8%CVE-2025-29826HIGHMicrosoft Dataverse Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2025-21363HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 0.8%CVE-2019-1380A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of PrivilegEPSS 0.8%