Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2023-29360HIGHMicrosoft Streaming Service Elevation of Privilege VulnerabilityEPSS 21.6%KEVCVE-2021-27078CRITICALMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 21.6%CVE-2018-8540—A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote EPSS 21.6%CVE-2019-1373—A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft ExEPSS 21.4%CVE-2019-5917—azure-umqtt-c (available through GitHub prior to 2017 October 6) allows remote attackers to cause a denial of service via unspecified vectorEPSS 21.4%CVE-2019-0795—A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote CodeEPSS 21.3%CVE-2020-1436—A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted fonts.For all systems exceptEPSS 21.3%CVE-2018-8626—A remote code execution vulnerability exists in Windows Domain Name System (DNS) servers when they fail to properly handle requests, aka "WiEPSS 21.2%CVE-2023-21692CRITICALMicrosoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution VulnerabilityEPSS 21.2%CVE-2025-47166HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 21.2%CVE-2023-36052HIGHAzure CLI REST Command Information Disclosure VulnerabilityEPSS 21.1%CVE-2020-0603—A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who suEPSS 21.0%CVE-2018-8281—A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka EPSS 20.8%CVE-2018-8312—A remote code execution vulnerability exists when Microsoft Access fails to properly handle objects in memory, aka "Microsoft Access Remote EPSS 20.8%CVE-2018-1029—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 20.8%CVE-2023-36563MEDIUMMicrosoft WordPad Information Disclosure VulnerabilityEPSS 20.7%KEVCVE-2024-49122HIGHMicrosoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityEPSS 20.7%CVE-2018-8460—A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory CorEPSS 20.7%CVE-2018-0920—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 20.6%CVE-2019-1127—A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution VEPSS 20.6%