Vulnerabilidades en microsoft
9312 resultadosAnálisis Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2023-28240HIGHWindows Network Load Balancing Remote Code Execution VulnerabilityEPSS 0.8%CVE-2022-26789HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-26791HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2020-0854—An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'WiEPSS 0.8%CVE-2019-1380—A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of PrivilegEPSS 0.8%CVE-2023-36428MEDIUMMicrosoft Local Security Authority Subsystem Service Information Disclosure VulnerabilityEPSS 0.8%CVE-2026-47643CRITICALAzure Stack Edge Remote Code Execution VulnerabilityEPSS 0.8%CVE-2022-24513HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2021-36967HIGHWindows WLAN AutoConfig Service Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-21340MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.8%CVE-2025-47160MEDIUMWindows Shortcut Files Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2019-1447—A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'MicrosofEPSS 0.8%CVE-2025-59200HIGHData Sharing Service Spoofing VulnerabilityEPSS 0.8%CVE-2026-57102HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2020-0935—An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneEPSS 0.8%CVE-2019-1445—A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'MicrosofEPSS 0.8%CVE-2025-21358HIGHWindows Core Messaging Elevation of Privileges VulnerabilityEPSS 0.8%CVE-2021-43246MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 0.8%CVE-2023-32051HIGHRaw Image Extension Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-20931HIGHWindows Telephony Service Elevation of Privilege VulnerabilityEPSS 0.8%