Vulnerabilidades em microsoft

9.364 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2021-42287HIGHActive Directory Domain Services Elevation of Privilege VulnerabilityEPSS 74.3%KEVCVE-2021-40449HIGHWin32k Elevation of Privilege VulnerabilityEPSS 74.1%KEVCVE-2018-8414HIGHA remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code ExEPSS 74.0%KEVCVE-2019-1458HIGHAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EPSS 73.9%KEVCVE-2019-1234A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.EPSS 73.7%CVE-2018-8120HIGHAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k EPSS 73.7%KEVCVE-2021-31195MEDIUMMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 73.7%CVE-2023-36039HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 73.0%CVE-2020-1421A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attaEPSS 72.9%CVE-2019-1429HIGHA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'ScripEPSS 72.6%KEVCVE-2024-20697HIGHWindows libarchive Remote Code Execution VulnerabilityEPSS 72.2%CVE-2026-21509HIGHMicrosoft Office Security Feature Bypass VulnerabilityEPSS 72.2%KEVCVE-2021-28480CRITICALMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 71.4%CVE-2019-0547A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, akaEPSS 71.4%CVE-2018-8229A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 71.3%CVE-2018-8279A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory CorruptioEPSS 71.0%CVE-2019-0887A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attackEPSS 71.0%CVE-2024-49112CRITICALWindows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityEPSS 70.9%CVE-2020-16952HIGHMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 70.9%CVE-2020-17143HIGHMicrosoft Exchange Server Information Disclosure VulnerabilityEPSS 70.6%