Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2018-8350—A remote code execution vulnerability exists when Microsoft Windows PDF Library improperly handles objects in memory, aka "Windows PDF RemotEPSS 18.6%CVE-2019-1372—An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to EPSS 18.5%CVE-2020-0964—A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 18.5%CVE-2019-0801—A remote code execution vulnerability exists when Microsoft Office fails to properly handle certain files.To exploit the vulnerability, an aEPSS 18.5%CVE-2018-8500—A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting EnginEPSS 18.5%CVE-2022-22718HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 18.5%KEVCVE-2019-1250—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 18.4%CVE-2019-1243—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 18.4%CVE-2019-1124—A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution VEPSS 18.4%CVE-2019-0674—A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka EPSS 18.4%CVE-2018-8440HIGHAn elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC), aka "Windows AEPSS 18.4%KEVCVE-2026-20925MEDIUMNTLM Hash Disclosure Spoofing VulnerabilityEPSS 18.2%CVE-2019-0793—A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote CodeEPSS 18.2%CVE-2019-0791—A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote CodeEPSS 18.2%CVE-2019-0792—A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote CodeEPSS 18.2%CVE-2018-8376—A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, EPSS 18.2%CVE-2019-0842—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine RemEPSS 18.0%CVE-2024-29990CRITICALMicrosoft Azure Kubernetes Service Confidential Container Elevation of Privilege VulnerabilityEPSS 18.0%CVE-2019-1462—A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, EPSS 18.0%CVE-2020-0995—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 17.8%