Vulnerabilidades em microsoft

9.364 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2023-28252HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 49.0%KEVCVE-2018-8420A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote CodeEPSS 48.9%CVE-2020-17117MEDIUMMicrosoft Exchange Remote Code Execution VulnerabilityEPSS 48.9%CVE-2019-1009MEDIUMWindows GDI Information Disclosure VulnerabilityEPSS 48.5%CVE-2021-40487HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 48.2%CVE-2019-1040MEDIUMWindows NTLM Tampering VulnerabilityEPSS 48.0%CVE-2018-8544A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine RemEPSS 47.6%CVE-2022-35748HIGHHTTP.sys Denial of Service VulnerabilityEPSS 47.2%CVE-2020-16875HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 47.1%CVE-2018-8413A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote CodeEPSS 46.4%CVE-2021-31196HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 46.4%KEVCVE-2022-34718CRITICALWindows TCP/IP Remote Code Execution VulnerabilityEPSS 46.4%CVE-2017-0176A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a rEPSS 45.9%CVE-2018-8619A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under EPSS 45.8%CVE-2021-34481HIGHWindows Print Spooler Remote Code Execution VulnerabilityEPSS 45.4%CVE-2019-0803HIGHAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EPSS 45.2%KEVCVE-2024-38024HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 45.2%CVE-2024-29988HIGHSmartScreen Prompt Security Feature Bypass VulnerabilityEPSS 45.2%KEVCVE-2019-1367HIGHA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'ScripEPSS 45.0%KEVCVE-2022-37954HIGHDirectX Graphics Kernel Elevation of Privilege VulnerabilityEPSS 44.9%