Vulnerabilidades em microsoft
9.312 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2021-38642MEDIUMMicrosoft Edge for iOS Spoofing VulnerabilityEPSS 1.1%CVE-2020-0635—An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'WindoEPSS 1.1%CVE-2020-0731—An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EPSS 1.1%CVE-2021-38641MEDIUMMicrosoft Edge for Android Spoofing VulnerabilityEPSS 1.1%CVE-2019-0973HIGHWindows Installer Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2022-22049HIGHWindows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2022-23281MEDIUMWindows Common Log File System Driver Information Disclosure VulnerabilityEPSS 1.1%CVE-2021-41333HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2022-41121HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 1.1%CVE-2024-49142HIGHMicrosoft Access Remote Code Execution VulnerabilityEPSS 1.1%CVE-2025-59254HIGHMicrosoft DWM Core Library Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2022-34702HIGHWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityEPSS 1.0%CVE-2025-21404MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 1.0%CVE-2019-0727—An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows fiEPSS 1.0%CVE-2023-21695HIGHMicrosoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution VulnerabilityEPSS 1.0%CVE-2019-1272—An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker whoEPSS 1.0%CVE-2019-1413—A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permissioEPSS 1.0%CVE-2021-43237HIGHWindows Setup Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2024-43601HIGHVisual Studio Code for Linux Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-26121HIGHAzure IOT Explorer Spoofing VulnerabilityEPSS 1.0%