Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2023-36767MEDIUMMicrosoft Office Security Feature Bypass VulnerabilityEPSS 3.1%CVE-2021-28454HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 3.1%CVE-2024-26219HIGHHTTP.sys Denial of Service VulnerabilityEPSS 3.1%CVE-2024-26254HIGHMicrosoft Virtual Machine Bus (VMBus) Denial of Service VulnerabilityEPSS 3.1%CVE-2020-1178—An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authenticatioEPSS 3.1%CVE-2019-0729—An Elevation of Privilege vulnerability exists in the way Azure IoT Java SDK generates symmetric keys for encryption, allowing an attacker tEPSS 3.1%CVE-2024-20696HIGHWindows libarchive Remote Code Execution VulnerabilityEPSS 3.1%CVE-2020-1259—A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'WindowEPSS 3.1%CVE-2020-16979MEDIUMMicrosoft SharePoint Information Disclosure VulnerabilityEPSS 3.1%CVE-2018-8315—An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting EnEPSS 3.1%CVE-2025-26645HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 3.1%CVE-2021-34528HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 3.1%CVE-2018-8306—A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does nEPSS 3.1%CVE-2020-1305—An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows EPSS 3.1%CVE-2020-1311—An elevation of privilege vulnerability exists when Component Object Model (COM) client uses special case IIDs, aka 'Component Object Model EPSS 3.1%CVE-2021-27052MEDIUMMicrosoft SharePoint Server Information Disclosure VulnerabilityEPSS 3.1%CVE-2021-24101MEDIUMMicrosoft Dataverse Information Disclosure VulnerabilityEPSS 3.1%CVE-2020-17156HIGHVisual Studio Remote Code Execution VulnerabilityEPSS 3.1%CVE-2021-33755MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 3.1%CVE-2020-1568HIGHMicrosoft Edge PDF Remote Code Execution VulnerabilityEPSS 3.1%