Exposição de Microsoft Excel

Editors
26
score de exposição
124
sites usam
1
em exploração
0
críticos
Análise Vexday

Com apenas 39 CVEs catalogadas, o Microsoft Excel apresenta volume relativamente contido de vulnerabilidades, mas sua taxa de exploração ativa está significativamente acima da média geral do catálogo — 5,7 vezes superior —, o que indica que as falhas historicamente identificadas nesta tecnologia tendem a ser aproveitadas na prática com frequência desproporcional. A CVE-2019-1297, a vulnerabilidade mais perigosa atualmente em exploração ativa, registra EPSS de 0,2046, sinalizando probabilidade não negligenciável de exploração observada em ambientes reais. O maior EPSS registrado entre as CVEs do produto chega a 0,28178, reforçando que ao menos parte do portfólio de vulnerabilidades continua relevante do ponto de vista operacional, mesmo sem registros de novas ocorrências nos últimos 90 dias. Equipes de segurança devem priorizar a verificação do status de correção das vulnerabilidades em KEV, dado o padrão histórico de exploração ativa acima da média.

CVEs

39 resultados
CVE-2019-1297HIGHA remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 21.8%KEVCVE-2019-1448A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 28.2%CVE-2018-8162A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 24.5%CVE-2018-8147A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 24.5%CVE-2018-8148A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 24.5%CVE-2018-0796Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execuEPSS 23.3%CVE-2018-0920A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 21.0%CVE-2018-1029A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 20.9%CVE-2018-1011A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 20.1%CVE-2018-8502A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected VieEPSS 19.8%CVE-2018-1027A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 19.2%CVE-2019-1331A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 19.1%CVE-2018-8577A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 19.1%CVE-2018-8574A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 19.1%CVE-2020-0650A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 17.2%CVE-2020-0651A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 17.2%CVE-2020-1226A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 17.2%CVE-2020-1225A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 17.2%CVE-2018-8379A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 17.1%CVE-2018-8375A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 16.2%