Vulnerabilidades em microsoft
10.822 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2023-38186HIGHWindows Mobile Device Management Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2021-34516HIGHWin32k Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2021-26892MEDIUMWindows Extensible Firmware Interface Security Feature Bypass VulnerabilityEPSS 1.3%CVE-2024-30020HIGHWindows Cryptographic Services Remote Code Execution VulnerabilityEPSS 1.3%CVE-2022-30200HIGHWindows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityEPSS 1.3%CVE-2024-38081HIGH.NET, .NET Framework, and Visual Studio Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2020-16984HIGHAzure Sphere Unsigned Code Execution VulnerabilityEPSS 1.3%CVE-2019-0936—An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'WindoEPSS 1.3%CVE-2023-33159HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.3%CVE-2020-1419—An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel InEPSS 1.3%CVE-2024-49035HIGHPartner.Microsoft.Com Elevation of Privilege VulnerabilityEPSS 1.3%KEVCVE-2020-0893MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.3%CVE-2020-0894MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.3%CVE-2020-0792—An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows GraphiEPSS 1.3%CVE-2020-1268—An information disclosure vulnerability exists when a Windows service improperly handles objects in memory, aka 'Windows Service InformationEPSS 1.3%CVE-2020-1261—An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error ReportEPSS 1.3%CVE-2020-1263—An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error ReportEPSS 1.3%CVE-2020-0622—An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'MicrEPSS 1.3%CVE-2020-1120—A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'ConnEPSS 1.3%CVE-2020-0820—An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation InformationEPSS 1.3%