Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2026-50522CRITICALMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 3.0%KEVCVE-2019-0941MEDIUMMicrosoft IIS Server Denial of Service VulnerabilityEPSS 3.0%CVE-2025-59501MEDIUMMicrosoft Configuration Manager Spoofing VulnerabilityEPSS 3.0%CVE-2021-27066MEDIUMWindows Admin Center Security Feature Bypass VulnerabilityEPSS 3.0%CVE-2019-1345—An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel InformationEPSS 3.0%CVE-2022-21889HIGHWindows Internet Key Exchange (IKE) Extension Denial of Service VulnerabilityEPSS 3.0%CVE-2022-21890HIGHWindows Internet Key Exchange (IKE) Extension Denial of Service VulnerabilityEPSS 3.0%CVE-2019-1043MEDIUMComctl32 Remote Code Execution VulnerabilityEPSS 3.0%CVE-2025-55694HIGHWindows Error Reporting Service Elevation of Privilege VulnerabilityEPSS 3.0%CVE-2020-1291—An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'WindoEPSS 3.0%CVE-2020-1314—An elevation of privilege vulnerability exists in Windows Text Service Framework (TSF) when the TSF server fails to properly handle messagesEPSS 3.0%CVE-2020-1280—An elevation of privilege vulnerability exists in the way that the Windows Bluetooth Service handles objects in memory, aka 'Windows BluetooEPSS 3.0%CVE-2020-1287—An elevation of privilege vulnerability exists in the way that the Windows WalletService handles objects in memory, aka 'Windows WalletServiEPSS 3.0%CVE-2020-1211—An elevation of privilege vulnerability exists in the way that the Connected Devices Platform Service handles objects in memory, aka 'ConnecEPSS 3.0%CVE-2020-1244—A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'ConnEPSS 3.0%CVE-2021-33764MEDIUMWindows Key Distribution Center Information Disclosure VulnerabilityEPSS 3.0%CVE-2018-8374—A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server TamperEPSS 3.0%CVE-2022-37998HIGHWindows Local Session Manager (LSM) Denial of Service VulnerabilityEPSS 3.0%CVE-2019-0875—An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOpEPSS 3.0%CVE-2022-21837HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 3.0%