Exposición de Windows Server

Operating systems
1432
score de exposición
228.411
sitios usan
32
en explotación
3
críticos
Análisis Vexday

Windows Server acumula 831 CVEs catalogadas, das quais 33 estão confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 8,8 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada. A CVE mais perigosa em atividade, CVE-2019-0708, registra EPSS de 1,0, sinalizando probabilidade máxima de exploração e exigindo atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O tipo de falha mais recorrente é CWE-59 (improper link resolution before file access, ou "link following"), sugerindo que controles de integridade de sistema de arquivos e privilégios de acesso devem compor a linha de defesa prioritária. Embora nenhuma CVE nova tenha surgido nos últimos 90 dias, o perfil histórico da plataforma — com 3 falhas críticas ativas e EPSS máximo observado de 0,99999 — reforça a necessidade de gestão contínua e rigorosa de patches.

CVEs

755 resultados
CVE-2019-1343A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. TEPSS 10.9%CVE-2020-1407A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 10.9%CVE-2019-1108An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory, aka 'Remote DeskEPSS 10.7%CVE-2020-0681A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote DeEPSS 10.6%CVE-2019-1453A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sendsEPSS 9.9%CVE-2019-0879A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 9.8%CVE-2019-1456A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially cEPSS 9.7%CVE-2019-0849An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 9.5%CVE-2019-0802An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 9.5%CVE-2020-0910A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated usEPSS 9.2%CVE-2020-1374A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote DeEPSS 9.1%CVE-2020-0684A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attaEPSS 9.0%CVE-2019-1484A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code EPSS 8.9%CVE-2020-1283A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.EPSS 8.8%CVE-2020-0611A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote DeEPSS 8.4%CVE-2019-0784A remote code execution vulnerability exists in the way that the ActiveX Data objects (ADO) handles objects in memory, aka 'Windows ActiveX EPSS 8.3%CVE-2019-1471A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated usEPSS 8.2%CVE-2019-0688An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP IEPSS 7.9%CVE-2019-0660An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.7%CVE-2019-0619An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.7%