Vulnerabilidades em microsoft
10.811 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2022-38009HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 2.1%CVE-2018-8216—A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerSheEPSS 2.1%CVE-2018-8211—A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerSheEPSS 2.1%CVE-2018-8215—A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerSheEPSS 2.1%CVE-2018-8217—A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerSheEPSS 2.1%CVE-2018-8221—A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerSheEPSS 2.1%CVE-2018-8222—A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerSheEPSS 2.1%CVE-2024-30042HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 2.1%CVE-2020-1323—An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could seEPSS 2.1%CVE-2022-35787MEDIUMAzure Site Recovery Elevation of Privilege VulnerabilityEPSS 2.1%CVE-2022-21968MEDIUMMicrosoft SharePoint Server Security Feature Bypass VulnerabilityEPSS 2.1%CVE-2022-35800MEDIUMAzure Site Recovery Elevation of Privilege VulnerabilityEPSS 2.1%CVE-2023-36697MEDIUMMicrosoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityEPSS 2.1%CVE-2018-8479—A spoofing vulnerability exists for the Azure IoT Device Provisioning for the C SDK library using the HTTP protocol on Windows platform, akaEPSS 2.1%CVE-2024-43609MEDIUMMicrosoft Office Spoofing VulnerabilityEPSS 2.1%CVE-2022-37955HIGHWindows Group Policy Elevation of Privilege VulnerabilityEPSS 2.1%CVE-2021-34468HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 2.1%CVE-2021-34497MEDIUMWindows MSHTML Platform Remote Code Execution VulnerabilityEPSS 2.1%CVE-2019-0814—An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information DisEPSS 2.1%CVE-2019-0848—An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information DisEPSS 2.1%