Vulnerabilidades en microsoft

9312 resultados
Análisis Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2023-28240HIGHWindows Network Load Balancing Remote Code Execution VulnerabilityEPSS 0.8%CVE-2022-26789HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-26791HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2020-0854An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'WiEPSS 0.8%CVE-2019-1380A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of PrivilegEPSS 0.8%CVE-2023-36428MEDIUMMicrosoft Local Security Authority Subsystem Service Information Disclosure VulnerabilityEPSS 0.8%CVE-2026-47643CRITICALAzure Stack Edge Remote Code Execution VulnerabilityEPSS 0.8%CVE-2022-24513HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2021-36967HIGHWindows WLAN AutoConfig Service Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2024-21340MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 0.8%CVE-2025-47160MEDIUMWindows Shortcut Files Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2019-1447A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'MicrosofEPSS 0.8%CVE-2025-59200HIGHData Sharing Service Spoofing VulnerabilityEPSS 0.8%CVE-2026-57102HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2020-0935An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneEPSS 0.8%CVE-2019-1445A spoofing vulnerability exists when Office Online does not validate origin in cross-origin communications handlers correctly, aka 'MicrosofEPSS 0.8%CVE-2025-21358HIGHWindows Core Messaging Elevation of Privileges VulnerabilityEPSS 0.8%CVE-2021-43246MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 0.8%CVE-2023-32051HIGHRaw Image Extension Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-20931HIGHWindows Telephony Service Elevation of Privilege VulnerabilityEPSS 0.8%