Vulnerabilidades em microsoft

9.331 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2026-42906MEDIUMWindows Shell Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-45594MEDIUMWindows Application Identity (AppID) Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-59184MEDIUMStorage Spaces Direct Information Disclosure VulnerabilityEPSS 0.4%CVE-2022-26808HIGHWindows File Explorer Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-49176HIGHWindows WalletService Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-26228HIGHWindows Cryptographic Services Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2024-43472MEDIUMMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-60718HIGHWindows Administrator Protection Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-49714HIGHVisual Studio Code Python Extension Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-40413HIGHWindows TCP/IP Denial of Service VulnerabilityEPSS 0.4%CVE-2023-21524HIGHWindows Local Security Authority (LSA) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-24049HIGHAzure Command Line Integration (CLI) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-38176HIGHAzure Arc-Enabled Servers Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2022-22008HIGHWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-42895MEDIUMMicrosoft Copilot Tampering VulnerabilityEPSS 0.4%CVE-2026-20956HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 0.4%CVE-2024-30031HIGHWindows CNG Key Isolation Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-20962MEDIUMDynamic Root of Trust for Measurement (DRTM) Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-42893HIGHMicrosoft Outlook for iOS Tampering VulnerabilityEPSS 0.4%CVE-2025-54363MEDIUMMicrosoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signEPSS 0.4%