Vulnerabilidades em microsoft

10.822 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2024-38061HIGHDCOM Remote Cross-Session Activation Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2020-1297MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.5%CVE-2022-21954MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2025-24051HIGHWindows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2024-38240HIGHWindows Remote Access Connection Manager Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2023-28268HIGHNetlogon RPC Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2023-21708CRITICALRemote Procedure Call Runtime Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-24767HIGHGitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.EPSS 1.5%CVE-2019-1163MEDIUMWindows File Signature Security Feature Bypass VulnerabilityEPSS 1.5%CVE-2023-36425HIGHWindows Distributed File System (DFS) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2020-17113MEDIUMWindows Camera Codec Information Disclosure VulnerabilityEPSS 1.5%CVE-2018-8164—An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k EPSS 1.5%CVE-2024-21350HIGHMicrosoft WDAC OLE DB provider for SQL Server Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-21838MEDIUMWindows Cleanup Manager Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2018-0854—A security feature bypass vulnerability exists in Windows Scripting Host which could allow an attacker to bypass Device Guard, aka "Windows EPSS 1.5%CVE-2020-17046MEDIUMWindows Error Reporting Denial of Service VulnerabilityEPSS 1.5%CVE-2026-21520HIGHCopilot Studio Information Disclosure VulnerabilityEPSS 1.5%CVE-2021-24113MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 1.5%CVE-2020-1474HIGHWindows Image Acquisition Service Information Disclosure VulnerabilityEPSS 1.5%CVE-2020-0754—An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error RepoEPSS 1.5%