Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2019-0688—An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, aka 'Windows TCP/IP IEPSS 7.9%CVE-2020-0812—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-bEPSS 7.9%CVE-2018-8218—A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privEPSS 7.9%CVE-2023-21710HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 7.9%CVE-2018-8351—An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft BroEPSS 7.9%CVE-2021-42305MEDIUMMicrosoft Exchange Server Spoofing VulnerabilityEPSS 7.9%CVE-2019-0779—A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory CorruptioEPSS 7.9%CVE-2022-21893HIGHRemote Desktop Protocol Remote Code Execution VulnerabilityEPSS 7.9%CVE-2023-36731HIGHWin32k Elevation of Privilege VulnerabilityEPSS 7.8%CVE-2019-1083—A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of SEPSS 7.8%CVE-2019-1056—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'ScripEPSS 7.8%CVE-2019-1059—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'ScripEPSS 7.8%CVE-2019-1004—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'ScripEPSS 7.8%CVE-2018-8357—An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "Microsoft Browser Elevation of Privilege EPSS 7.8%CVE-2019-1263—An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 7.8%CVE-2019-1390—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code ExecutEPSS 7.8%CVE-2021-31985HIGHMicrosoft Defender Remote Code Execution VulnerabilityEPSS 7.8%CVE-2019-1489—An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, akEPSS 7.7%CVE-2020-0811—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-bEPSS 7.7%CVE-2025-53786HIGHMicrosoft Exchange Server Hybrid Deployment Elevation of Privilege VulnerabilityEPSS 7.7%