Vulnerabilities in microsoft

9,312 results
Vexday analysis

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2025-53762HIGHMicrosoft Purview Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2020-1346An elevation of privilege vulnerability exists when the Windows Modules Installer improperly handles file operations, aka 'Windows Modules IEPSS 0.7%CVE-2020-1463An elevation of privilege vulnerability exists in the way that the SharedStream Library handles objects in memory, aka 'Windows SharedStreamEPSS 0.7%CVE-2023-21805HIGHWindows MSHTML Platform Remote Code Execution VulnerabilityEPSS 0.7%CVE-2020-1352An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an EPSS 0.7%CVE-2024-49031HIGHMicrosoft Office Graphics Remote Code Execution VulnerabilityEPSS 0.7%CVE-2020-1078An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operatioEPSS 0.7%CVE-2024-49021HIGHMicrosoft SQL Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-49030HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.7%CVE-2020-1363An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an EPSS 0.7%CVE-2024-49027HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-49029HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-43106HIGHA library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileEPSS 0.7%CVE-2024-42220HIGHA library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access pEPSS 0.7%CVE-2024-49028HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-21193MEDIUMActive Directory Federation Server Spoofing VulnerabilityEPSS 0.7%CVE-2020-1371An elevation of privilege vulnerability exists when the Windows Event Logging Service improperly handles memory.To exploit this vulnerabilitEPSS 0.7%CVE-2024-41165HIGHA library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privilegeEPSS 0.7%CVE-2024-28921MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2024-28903MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.7%