Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2018-8136—A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka "Windows Remote Code Execution VulnerabiEPSS 23.4%CVE-2018-8527—An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containingEPSS 23.4%CVE-2018-8533—An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containinEPSS 23.4%CVE-2018-8532—An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containinEPSS 23.4%CVE-2021-36948HIGHWindows Update Medic Service Elevation of Privilege VulnerabilityEPSS 23.3%KEVCVE-2018-1013—A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "MicrosoEPSS 23.3%CVE-2018-1012—A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "MicrosoEPSS 23.3%CVE-2018-1015—A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "MicrosoEPSS 23.3%CVE-2025-33071HIGHWindows KDC Proxy Service (KPSSVC) Remote Code Execution VulnerabilityEPSS 23.2%CVE-2019-0940—A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory CorrEPSS 23.1%CVE-2018-8430—A remote code execution vulnerability exists in Microsoft Word if a user opens a specially crafted PDF file, aka "Word PDF Remote Code ExecuEPSS 23.0%CVE-2025-24071MEDIUMMicrosoft Windows File Explorer Spoofing VulnerabilityEPSS 22.9%CVE-2019-0592—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'CEPSS 22.9%CVE-2018-1003—A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, akEPSS 22.8%CVE-2024-21320MEDIUMWindows Themes Spoofing VulnerabilityEPSS 22.8%CVE-2021-26419HIGHScripting Engine Memory Corruption VulnerabilityEPSS 22.8%CVE-2018-8392—A buffer overflow vulnerability exists in the Microsoft JET Database Engine that could allow remote code execution on an affected system, akEPSS 22.8%CVE-2018-8349—A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "MicrosEPSS 22.7%CVE-2018-8256—A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote CoEPSS 22.6%CVE-2018-8629—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 22.6%