Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2018-0946—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "ScriptinEPSS 51.8%CVE-2021-34501HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 51.4%CVE-2021-34478HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 51.2%CVE-2024-38018HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 51.2%CVE-2021-36952HIGHVisual Studio Remote Code Execution VulnerabilityEPSS 51.2%CVE-2024-38030MEDIUMWindows Themes Spoofing VulnerabilityEPSS 51.1%CVE-2018-8552—An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attackeEPSS 51.0%CVE-2024-38094HIGHMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 50.9%KEVCVE-2018-8133—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 50.9%CVE-2021-28474HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 50.8%CVE-2018-8495—A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution VulnerabilEPSS 50.7%CVE-2022-37961HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 50.7%CVE-2021-26414MEDIUMWindows DCOM Server Security Feature BypassEPSS 49.8%CVE-2019-0785—A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failoEPSS 49.6%CVE-2023-36756HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 49.2%CVE-2023-28252HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 49.0%KEVCVE-2018-8420—A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote CodeEPSS 48.9%CVE-2020-17117MEDIUMMicrosoft Exchange Remote Code Execution VulnerabilityEPSS 48.9%CVE-2019-0768—A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under spEPSS 48.5%CVE-2019-1009MEDIUMWindows GDI Information Disclosure VulnerabilityEPSS 48.5%