Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2019-1300—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'CEPSS 8.7%CVE-2020-0939—An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation InformationEPSS 8.7%CVE-2024-20698HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 8.6%CVE-2020-1073—A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting EnginEPSS 8.6%CVE-2018-8627—An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, whiEPSS 8.6%CVE-2018-8160—An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure VulnerabilEPSS 8.6%CVE-2023-33145MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 8.6%CVE-2020-0640—A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory CorEPSS 8.6%CVE-2018-8213—A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka "Windows Remote Code Execution VulnerabiEPSS 8.6%CVE-2019-1388HIGHAn elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'WinEPSS 8.6%KEVCVE-2024-49040HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 8.5%CVE-2019-0971—An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specEPSS 8.5%CVE-2018-8493—An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka "Windows TCP/IP IEPSS 8.4%CVE-2026-20860HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 8.4%CVE-2019-0564—A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service VulnerabilitEPSS 8.4%CVE-2019-1224HIGHRemote Desktop Protocol Server Information Disclosure VulnerabilityEPSS 8.4%CVE-2018-8305—An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client Information DisclosEPSS 8.4%CVE-2019-1485—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code ExecutEPSS 8.4%CVE-2023-36399HIGHWindows Storage Elevation of Privilege VulnerabilityEPSS 8.3%CVE-2021-28310HIGHWin32k Elevation of Privilege VulnerabilityEPSS 8.3%KEV