Vulnerabilidades em Microsoft

10.811 resultados
Análise Vexday

Com 8.642 CVEs catalogadas e 248 confirmadas em exploração ativa pelo CISA KEV, a taxa de exploração do portfólio Microsoft está 6,4 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada em relação ao universo de vendors monitorados. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade com alto potencial de execução arbitrária de código e historicamente difícil de mitigar em escala. A CVE mais crítica atualmente em exploração ativa é CVE-2019-0708, com EPSS de 1,0 — o valor máximo da escala —, sinalizando probabilidade de exploração praticamente certa no curto prazo e exigindo atenção prioritária em ambientes onde a correção ainda não foi aplicada. Os 561 registros surgidos nos últimos 90 dias, combinados com 320 CVEs com prova de conceito pública, reforçam a necessidade de ciclos de patching contínuos e monitoramento ativo de exposição.

CVE-2024-21403CRITICALMicrosoft Azure Kubernetes Service Confidential Container Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2019-1274—An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel InEPSS 1.3%CVE-2025-21221HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.3%CVE-2020-1194—A denial of service vulnerability exists when Windows Registry improperly handles filesystem operations, aka 'Windows Registry Denial of SerEPSS 1.3%CVE-2016-9486—On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because files are created in a folder with incorrect privilegesEPSS 1.3%CVE-2016-9485—On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because it fails to set any permissions on downloaded file objectsEPSS 1.3%CVE-2022-24495HIGHWindows Direct Show Remote Code Execution VulnerabilityEPSS 1.3%CVE-2019-0632—A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security FeaturEPSS 1.3%CVE-2019-0631—A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security FeaturEPSS 1.3%CVE-2024-20679MEDIUMAzure Stack Hub Spoofing VulnerabilityEPSS 1.3%CVE-2021-36959MEDIUMWindows Authenticode Spoofing VulnerabilityEPSS 1.3%CVE-2020-17135MEDIUMAzure DevOps Server Spoofing VulnerabilityEPSS 1.3%CVE-2026-59864CRITICALKiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensionsEPSS 1.3%CVE-2025-29958MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.3%CVE-2025-21408HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.3%CVE-2025-29961MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.3%CVE-2026-23666HIGH.NET Framework Denial of Service VulnerabilityEPSS 1.3%CVE-2020-1505MEDIUMMicrosoft SharePoint Information Disclosure VulnerabilityEPSS 1.3%CVE-2020-1075MEDIUMWindows Subsystem for Linux Information Disclosure VulnerabilityEPSS 1.3%CVE-2025-30384HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 1.3%