Exposição de Windows Server

Operating systems
1.432
score de exposição
228.411
sites usam
32
em exploração
3
críticos
Análise Vexday

Windows Server acumula 831 CVEs catalogadas, das quais 33 estão confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 8,8 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada. A CVE mais perigosa em atividade, CVE-2019-0708, registra EPSS de 1,0, sinalizando probabilidade máxima de exploração e exigindo atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O tipo de falha mais recorrente é CWE-59 (improper link resolution before file access, ou "link following"), sugerindo que controles de integridade de sistema de arquivos e privilégios de acesso devem compor a linha de defesa prioritária. Embora nenhuma CVE nova tenha surgido nos últimos 90 dias, o perfil histórico da plataforma — com 3 falhas críticas ativas e EPSS máximo observado de 0,99999 — reforça a necessidade de gestão contínua e rigorosa de patches.

CVEs

755 resultados
CVE-2019-1333A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote DeEPSS 15.9%CVE-2019-0794A remote code execution vulnerability exists when OLE automation improperly handles objects in memory, aka 'OLE Automation Remote Code ExecuEPSS 15.5%CVE-2019-0662A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 15.4%CVE-2019-1347A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. TEPSS 14.9%CVE-2019-0845A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCvt Interface Remote CEPSS 14.8%CVE-2020-1208A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 14.7%CVE-2020-1281A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code EPSS 14.5%CVE-2020-1299A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attaEPSS 14.5%CVE-2019-0885A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code EPSS 14.4%CVE-2019-0765A remote code execution vulnerability exists in the way that comctl32.dll handles objects in memory, aka 'Comctl32 Remote Code Execution VulEPSS 14.3%CVE-2020-1412A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft GraphicsEPSS 14.0%CVE-2019-1060A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote CodeEPSS 13.8%CVE-2020-1435A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 13.7%CVE-2019-0896A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%CVE-2019-0890A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%CVE-2019-0895A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%CVE-2019-0900A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%CVE-2019-0893A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%CVE-2019-0894A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%CVE-2019-0901A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%