Vulnerabilidades em microsoft
10.822 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2026-45498MEDIUMMicrosoft Defender Denial of Service VulnerabilityEPSS 1.3%KEVCVE-2025-29830MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.3%CVE-2026-20803HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2025-29832MEDIUMWindows Routing and Remote Access Service (RRAS) Information Disclosure VulnerabilityEPSS 1.3%CVE-2025-21282HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.3%CVE-2025-21286HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.3%CVE-2025-21273HIGHWindows Telephony Service Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-33144MEDIUMVisual Studio Code Spoofing VulnerabilityEPSS 1.3%CVE-2024-21390HIGHMicrosoft Authenticator Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2019-1053MEDIUMWindows Shell Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2024-38129HIGHWindows Kerberos Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2024-37987HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 1.3%CVE-2024-38011HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 1.3%CVE-2024-37975HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 1.3%CVE-2020-1361—An information disclosure vulnerability exists in the way that the WalletService handles memory.To exploit the vulnerability, an attacker woEPSS 1.3%CVE-2023-41774HIGHLayer 2 Tunneling Protocol Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-41773HIGHLayer 2 Tunneling Protocol Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-55440MEDIUMMicrosoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of serviceEPSS 1.3%CVE-2022-22035HIGHWindows Point-to-Point Tunneling Protocol Remote Code Execution VulnerabilityEPSS 1.3%CVE-2020-17020LOWMicrosoft Word Security Feature Bypass VulnerabilityEPSS 1.3%