Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2024-38206HIGHMicrosoft Copilot Studio Information Disclosure VulnerabilityEPSS 12.3%CVE-2019-0758—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 12.3%CVE-2019-0582—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database EnEPSS 12.3%CVE-2023-28218HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 12.3%CVE-2024-26158HIGHMicrosoft Install Service Elevation of Privilege VulnerabilityEPSS 12.3%CVE-2018-8382—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel InEPSS 12.3%CVE-2018-8429—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel InEPSS 12.3%CVE-2019-0605—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'ScriptinEPSS 12.2%CVE-2018-8243—A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting EnginEPSS 12.2%CVE-2023-36424HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 12.2%KEVCVE-2019-0721—A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an aEPSS 12.1%CVE-2019-1244—An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite InformatioEPSS 12.1%CVE-2019-0594—A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application paEPSS 12.1%CVE-2019-0639—A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting EnginEPSS 12.0%CVE-2023-21715HIGHMicrosoft Publisher Security Feature Bypass VulnerabilityEPSS 12.0%KEVCVE-2020-17083MEDIUMMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 12.0%CVE-2023-36033HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 12.0%KEVCVE-2020-0960—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 12.0%CVE-2020-0999—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 12.0%CVE-2020-0889—A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 12.0%