Vulnerabilidades en microsoft

9766 resultados
Análisis Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2019-1166A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (MessageEPSS 68.1%CVE-2022-34713HIGHMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityEPSS 68.0%KEVCVE-2018-8397A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 67.9%CVE-2020-0610A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to theEPSS 67.6%CVE-2022-41034HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 67.5%CVE-2023-24950MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 67.5%CVE-2021-36934HIGHWindows Elevation of Privilege VulnerabilityEPSS 67.3%KEVCVE-2023-36606HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 67.2%CVE-2019-0618A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 67.0%CVE-2018-8145An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker EPSS 66.9%CVE-2024-43572HIGHMicrosoft Management Console Remote Code Execution VulnerabilityEPSS 66.6%KEVCVE-2018-0980A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 66.6%CVE-2018-8139A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "ScriptinEPSS 66.6%CVE-2018-0953A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "ScriptinEPSS 66.6%CVE-2021-36942HIGHWindows LSA Spoofing VulnerabilityEPSS 66.0%KEVCVE-2025-55315CRITICALASP.NET Security Feature Bypass VulnerabilityEPSS 65.8%CVE-2020-0655A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated atEPSS 65.7%CVE-2023-21768HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 65.4%CVE-2020-1020HIGHA remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a speciallyEPSS 65.0%KEVCVE-2026-32202MEDIUMWindows Shell Spoofing VulnerabilityEPSS 63.7%KEV