Vulnerabilidades em microsoft
10.822 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2019-1370—An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open EnclavEPSS 1.6%CVE-2024-21369HIGHMicrosoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityEPSS 1.5%CVE-2023-21563MEDIUMBitLocker Security Feature Bypass VulnerabilityEPSS 1.5%CVE-2019-1273—A cross-site-scripting (XSS) vulnerability exists when Active Directory Federation Services (ADFS) does not properly sanitize certain error EPSS 1.5%CVE-2025-27477HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.5%CVE-2020-17010HIGHWin32k Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2019-1362—An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, akEPSS 1.5%CVE-2020-0795MEDIUMThis vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.EPSS 1.5%CVE-2024-45383MEDIUMA mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus Driver 10.0.19041.36EPSS 1.5%CVE-2024-30024HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2023-28260HIGH.NET DLL Hijacking Remote Code Execution VulnerabilityEPSS 1.5%CVE-2024-30023HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2024-30022HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-34708MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.5%CVE-2024-49018HIGHSQL Server Native Client Remote Code Execution VulnerabilityEPSS 1.5%CVE-2025-47954HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2022-44684MEDIUMWindows Local Session Manager (LSM) Denial of Service VulnerabilityEPSS 1.5%CVE-2024-49082MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 1.5%CVE-2019-1305—A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team FounEPSS 1.5%CVE-2019-1490—A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for BusiEPSS 1.5%