Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2020-0961—A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka EPSS 11.8%CVE-2020-0855—A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft WEPSS 11.8%CVE-2020-0991—A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka EPSS 11.8%CVE-2023-0755CRITICAL The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remoteEPSS 11.8%CVE-2020-1286—A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploEPSS 11.8%CVE-2018-8468—An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." EPSS 11.8%CVE-2022-29104HIGHWindows Print Spooler Elevation of Privilege VulnerabilityEPSS 11.8%CVE-2023-41772HIGHWin32k Elevation of Privilege VulnerabilityEPSS 11.8%CVE-2018-0949—A security feature bypass vulnerability exists when Microsoft Internet Explorer improperly handles requests involving UNC resources, aka "InEPSS 11.7%CVE-2023-23383HIGHService Fabric Explorer Spoofing VulnerabilityEPSS 11.7%CVE-2020-1409—A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution VEPSS 11.7%CVE-2020-0967—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code ExecutEPSS 11.7%CVE-2020-0966—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code ExecutEPSS 11.7%CVE-2019-1257—A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application paEPSS 11.7%CVE-2018-8177—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 11.7%CVE-2023-36594HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 11.6%CVE-2021-26897CRITICALWindows DNS Server Remote Code Execution VulnerabilityEPSS 11.6%CVE-2019-1253HIGHAn elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerabEPSS 11.6%KEVCVE-2019-1419—A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially cEPSS 11.6%CVE-2020-1321—A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka 'MicrosoftEPSS 11.6%