Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2018-8542—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 14.2%CVE-2018-8557—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 14.2%CVE-2018-8555—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 14.2%CVE-2018-8556—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 14.2%CVE-2020-1337HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 14.1%CVE-2023-38180HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 14.0%KEVCVE-2020-1412—A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft GraphicsEPSS 14.0%CVE-2019-1327—A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 14.0%CVE-2020-17136HIGHWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityEPSS 14.0%CVE-2018-8301—A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory CorruptioEPSS 13.9%CVE-2025-29824HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 13.9%KEVCVE-2018-8226—A denial of service vulnerability exists in the HTTP 2.0 protocol stack (HTTP.sys) when HTTP.sys improperly parses specially crafted HTTP 2.EPSS 13.9%CVE-2019-1149HIGHMicrosoft Graphics Remote Code Execution VulnerabilityEPSS 13.9%CVE-2019-1430—A remote code execution vulnerability exists when Windows Media Foundation improperly parses specially crafted QuickTime media files.An attaEPSS 13.8%CVE-2020-17049MEDIUMKerberos KDC Security Feature Bypass VulnerabilityEPSS 13.8%CVE-2019-1060—A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote CodeEPSS 13.8%CVE-2020-1435—A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 13.7%CVE-2020-1248—A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 13.7%CVE-2019-0901—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%CVE-2019-0897—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 13.7%