Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2021-1647HIGHMicrosoft Defender Remote Code Execution VulnerabilityEPSS 39.4%KEVCVE-2023-36050HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 39.2%CVE-2020-1313—An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'WindowsEPSS 39.0%CVE-2020-1464HIGHWindows Spoofing VulnerabilityEPSS 38.9%KEVCVE-2021-28476CRITICALWindows Hyper-V Remote Code Execution VulnerabilityEPSS 38.6%CVE-2025-21277HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 38.6%CVE-2022-37985MEDIUMWindows Graphics Component Information Disclosure VulnerabilityEPSS 38.6%CVE-2018-8474—A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for MEPSS 38.2%CVE-2023-33157HIGHMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 38.2%CVE-2022-24500HIGHWindows SMB Remote Code Execution VulnerabilityEPSS 38.0%CVE-2022-34689HIGHWindows CryptoAPI Spoofing VulnerabilityEPSS 37.9%CVE-2023-38146HIGHWindows Themes Remote Code Execution VulnerabilityEPSS 37.4%CVE-2022-22017HIGHRemote Desktop Client Remote Code Execution VulnerabilityEPSS 37.1%CVE-2023-36757HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 36.9%CVE-2023-28231HIGHDHCP Server Service Remote Code Execution VulnerabilityEPSS 36.6%CVE-2020-17144HIGHMicrosoft Exchange Remote Code Execution VulnerabilityEPSS 36.5%KEVCVE-2024-43464HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 36.3%CVE-2022-37974MEDIUMWindows Mixed Reality Developer Tools Information Disclosure VulnerabilityEPSS 36.3%CVE-2021-28481CRITICALMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 36.2%CVE-2019-1311—A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API RemEPSS 36.2%