Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2019-0615—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.7%CVE-2019-0664—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.7%CVE-2019-0660—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.7%CVE-2019-0616—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.7%CVE-2019-0602—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.7%CVE-2019-0658—An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'EPSS 7.7%CVE-2019-0619—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 7.7%CVE-2023-38148HIGHInternet Connection Sharing (ICS) Remote Code Execution VulnerabilityEPSS 7.7%CVE-2018-8251—A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka "Media Foundation Memory CoEPSS 7.7%CVE-2025-59246CRITICALAzure Entra ID Elevation of Privilege VulnerabilityEPSS 7.7%CVE-2019-1384—A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this EPSS 7.6%CVE-2022-23299HIGHWindows PDEV Elevation of Privilege VulnerabilityEPSS 7.6%CVE-2020-0602—A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service VulnerabilitEPSS 7.6%CVE-2019-0537—An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the victim opens a malicioEPSS 7.6%CVE-2020-0683HIGHAn elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer EleEPSS 7.6%KEVCVE-2025-53144HIGHMicrosoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityEPSS 7.6%CVE-2025-53145HIGHMicrosoft Message Queuing (MSMQ) Remote Code Execution VulnerabilityEPSS 7.6%CVE-2019-1222CRITICALRemote Desktop Services Remote Code Execution VulnerabilityEPSS 7.6%CVE-2018-8340—A security feature bypass vulnerability exists when Active Directory Federation Services (AD FS) improperly handles multi-factor authenticatEPSS 7.6%CVE-2023-23416HIGHWindows Cryptographic Services Remote Code Execution VulnerabilityEPSS 7.6%