Vulnerabilidades en Microsoft Corporation

865 resultados
Análisis Vexday

Com 30 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Microsoft Corporation apresenta uma taxa de exploração 7,7 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada em relação ao universo de vendors monitorados. O tipo de falha mais recorrente é CWE-119 (corrupção de memória por escrita ou leitura fora dos limites), padrão historicamente associado a impacto elevado e exploração confiável em ambientes reais. A CVE mais perigosa atualmente ativa é CVE-2017-11882, com EPSS de 0,9995 — praticamente a probabilidade máxima de exploração —, sinalizando que esta vulnerabilidade específica deve ser tratada como prioridade imediata em qualquer programa de gestão de patches. A presença de 216 CVEs com prova de conceito pública, num universo total de 865 registros, amplia a superfície de risco para organizações que ainda não tenham aplicado as correções disponíveis.

CVE-2017-8507—A remote code execution vulnerability exists in the way Microsoft Office software parses specially crafted email messages, aka "Microsoft OfEPSS 19.6%CVE-2017-11769—The Microsoft Windows TRIE component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code executEPSS 19.6%CVE-2018-0852—Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1 and RT SP1, Microsoft Outlook 2016, and Microsoft Office EPSS 19.4%CVE-2018-0795—Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects aEPSS 19.3%CVE-2018-0851—Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2EPSS 19.1%CVE-2017-0197—Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "MicrEPSS 19.1%CVE-2017-8527—Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 GoldEPSS 19.0%CVE-2017-0204—Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypEPSS 19.0%CVE-2017-0028—A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could EPSS 18.9%CVE-2017-11935—Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "MicroEPSS 18.9%CVE-2018-0849—Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allEPSS 18.6%CVE-2018-0862—Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allEPSS 18.6%CVE-2017-0265—Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory,EPSS 18.6%CVE-2017-8565—Windows PowerShell in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, WindoEPSS 18.5%CVE-2017-8509—A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office REPSS 18.2%CVE-2017-0196—An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process mEPSS 18.2%CVE-2017-0238—A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "ScEPSS 18.1%CVE-2017-0022MEDIUMMicrosoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 EPSS 18.1%KEVCVE-2018-0922—Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office CompatibilEPSS 18.0%CVE-2017-8744—A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, MiEPSS 17.9%