Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2020-17142CRITICALMicrosoft Exchange Remote Code Execution VulnerabilityEPSS 3.4%CVE-2019-1265—A security feature bypass vulnerability exists when Microsoft Yammer App for Android fails to apply the correct Intune MAM Policy.This couldEPSS 3.4%CVE-2020-1255—An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handlesEPSS 3.4%CVE-2022-21843HIGHWindows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution VulnerabilityEPSS 3.4%CVE-2026-21238HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 3.4%CVE-2019-0683—An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trustEPSS 3.4%CVE-2020-16977HIGHVisual Studio Code Python Extension Remote Code Execution VulnerabilityEPSS 3.4%CVE-2024-38242HIGHKernel Streaming Service Driver Elevation of Privilege VulnerabilityEPSS 3.4%CVE-2024-29996HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 3.4%CVE-2020-17159HIGHVisual Studio Code Java Extension Pack Remote Code Execution VulnerabilityEPSS 3.3%CVE-2019-1055HIGHScripting Engine Memory Corruption VulnerabilityEPSS 3.3%CVE-2019-1005HIGHScripting Engine Memory Corruption VulnerabilityEPSS 3.3%CVE-2021-1721MEDIUM.NET Core and Visual Studio Denial of Service VulnerabilityEPSS 3.3%CVE-2019-1425—An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka EPSS 3.3%CVE-2019-1398—A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated usEPSS 3.3%CVE-2020-17090MEDIUMMicrosoft Defender for Endpoint Security Feature Bypass VulnerabilityEPSS 3.3%CVE-2022-24490HIGHWindows Hyper-V Shared Virtual Hard Disks Information Disclosure VulnerabilityEPSS 3.3%CVE-2020-16954HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 3.3%CVE-2020-1209—An elevation of privilege vulnerability exists in the way that the Windows Network List Service handles objects in memory, aka 'Windows NetwEPSS 3.3%CVE-2020-1294—An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletServiEPSS 3.3%