Vulnerabilidades em Microsoft Corporation

865 resultados
Análise Vexday

Com 30 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Microsoft Corporation apresenta uma taxa de exploração 7,7 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada em relação ao universo de vendors monitorados. O tipo de falha mais recorrente é CWE-119 (corrupção de memória por escrita ou leitura fora dos limites), padrão historicamente associado a impacto elevado e exploração confiável em ambientes reais. A CVE mais perigosa atualmente ativa é CVE-2017-11882, com EPSS de 0,9995 — praticamente a probabilidade máxima de exploração —, sinalizando que esta vulnerabilidade específica deve ser tratada como prioridade imediata em qualquer programa de gestão de patches. A presença de 216 CVEs com prova de conceito pública, num universo total de 865 registros, amplia a superfície de risco para organizações que ainda não tenham aplicado as correções disponíveis.

CVE-2018-0937ChakraCore and Microsoft Windows 10 1703 and 1709 allow remote code execution, due to how the Chakra scripting engine handles objects in memEPSS 15.6%CVE-2017-0208An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memoryEPSS 15.3%CVE-2017-8625Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code IntEPSS 15.3%CVE-2017-0150A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0132A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0151A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0035A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0131A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0137A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0138A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0136A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0067A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0032A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in MicroEPSS 15.2%CVE-2017-0068Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "MicrosoftEPSS 15.2%CVE-2017-8644Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to theEPSS 15.1%CVE-2018-0858ChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory EPSS 15.1%CVE-2018-0861Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows remote code execution, due to how the scripting engine hanEPSS 15.1%CVE-2018-0883Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10EPSS 15.1%CVE-2018-0744The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 anEPSS 15.0%CVE-2018-0891ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows ServerEPSS 14.7%