Vulnerabilidades en microsoft
9766 resultadosAnálisis Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2019-1166—A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (MessageEPSS 68.1%CVE-2022-34713HIGHMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityEPSS 68.0%KEVCVE-2018-8397—A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 67.9%CVE-2020-0610—A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to theEPSS 67.6%CVE-2022-41034HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 67.5%CVE-2023-24950MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 67.5%CVE-2021-36934HIGHWindows Elevation of Privilege VulnerabilityEPSS 67.3%KEVCVE-2023-36606HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 67.2%CVE-2019-0618—A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 67.0%CVE-2018-8145—An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker EPSS 66.9%CVE-2024-43572HIGHMicrosoft Management Console Remote Code Execution VulnerabilityEPSS 66.6%KEVCVE-2018-0980—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 66.6%CVE-2018-8139—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "ScriptinEPSS 66.6%CVE-2018-0953—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "ScriptinEPSS 66.6%CVE-2021-36942HIGHWindows LSA Spoofing VulnerabilityEPSS 66.0%KEVCVE-2025-55315CRITICALASP.NET Security Feature Bypass VulnerabilityEPSS 65.8%CVE-2020-0655—A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated atEPSS 65.7%CVE-2023-21768HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 65.4%CVE-2020-1020HIGHA remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a speciallyEPSS 65.0%KEVCVE-2026-32202MEDIUMWindows Shell Spoofing VulnerabilityEPSS 63.7%KEV