Vulnerabilidades em microsoft
10.808 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2018-8298HIGHA remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting EnginEPSS 74.5%KEVCVE-2020-1421—A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attaEPSS 74.5%CVE-2019-1458HIGHAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EPSS 74.3%KEVCVE-2021-40449HIGHWin32k Elevation of Privilege VulnerabilityEPSS 74.1%KEVCVE-2018-8414HIGHA remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code ExEPSS 74.0%KEVCVE-2021-31195MEDIUMMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 73.7%CVE-2018-8120HIGHAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k EPSS 73.4%KEVCVE-2021-42278HIGHActive Directory Domain Services Elevation of Privilege VulnerabilityEPSS 73.3%KEVCVE-2022-30136CRITICALWindows Network File System Remote Code Execution VulnerabilityEPSS 73.2%CVE-2023-36039HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 73.0%CVE-2026-33824CRITICALWindows Internet Key Exchange (IKE) Service Extensions Remote Code Execution VulnerabilityEPSS 72.7%KEVCVE-2026-21509HIGHMicrosoft Office Security Feature Bypass VulnerabilityEPSS 72.6%KEVCVE-2024-20697HIGHWindows libarchive Remote Code Execution VulnerabilityEPSS 72.2%CVE-2024-49112CRITICALWindows Lightweight Directory Access Protocol (LDAP) Remote Code Execution VulnerabilityEPSS 71.9%CVE-2026-42897HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 71.8%KEVCVE-2019-0547—A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, akaEPSS 71.4%CVE-2021-28480CRITICALMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 71.2%CVE-2020-16952HIGHMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 71.1%CVE-2018-8229—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 71.0%CVE-2019-0887—A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attackEPSS 71.0%