Exposição de Microsoft SharePoint

CMS
15
score de exposição
2.158
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades do Microsoft SharePoint no catálogo soma 52 CVEs, nenhuma das quais está atualmente confirmada em exploração ativa pelo CISA KEV, resultado abaixo da média geral do catálogo. Não há registros de severidade crítica nem de novas vulnerabilidades surgidas nos últimos 90 dias, o que indica um período recente de relativa estabilidade para a plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora comum em aplicações web, exige atenção continuada em ambientes corporativos onde o SharePoint processa conteúdo de múltiplos usuários. A CVE com maior pontuação EPSS no conjunto é CVE-2019-0585, com valor de aproximadamente 0,22, sugerindo probabilidade moderada de tentativa de exploração — organizações que ainda mantêm versões antigas do produto devem verificar se essa vulnerabilidade foi devidamente remediada.

CVEs

52 resultados
CVE-2019-0585A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft WEPSS 19.8%CVE-2018-8161A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka EPSS 19.5%CVE-2018-1028A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "MiEPSS 17.1%CVE-2018-8628A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, EPSS 15.4%CVE-2018-8300A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application paEPSS 12.6%CVE-2018-8578An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering speEPSS 5.7%CVE-2018-8378An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, whEPSS 5.7%CVE-2018-8635An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authenticatioEPSS 5.2%CVE-2018-0790Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege EPSS 4.9%CVE-2017-8551An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aEPSS 4.9%CVE-2017-8514An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aEPSS 4.9%CVE-2018-8580An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cEPSS 4.4%CVE-2018-8518An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 4.1%CVE-2018-0923Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanEPSS 4.1%CVE-2018-0921Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanEPSS 4.1%CVE-2018-0911Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how sEPSS 4.1%CVE-2018-0917Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanEPSS 4.1%CVE-2018-0916Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how sEPSS 4.1%CVE-2018-0910Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how sEPSS 4.1%CVE-2018-0915Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how sEPSS 4.1%