Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2021-26895CRITICALWindows DNS Server Remote Code Execution VulnerabilityEPSS 7.3%CVE-2021-26894CRITICALWindows DNS Server Remote Code Execution VulnerabilityEPSS 7.3%CVE-2018-8416—A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This afEPSS 7.3%CVE-2023-36391HIGHLocal Security Authority Subsystem Service Elevation of Privilege VulnerabilityEPSS 7.2%CVE-2023-35641HIGHInternet Connection Sharing (ICS) Remote Code Execution VulnerabilityEPSS 7.2%CVE-2020-0824—A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory CorEPSS 7.2%CVE-2026-20805MEDIUMDesktop Window Manager Information Disclosure VulnerabilityEPSS 7.2%KEVCVE-2020-1213—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code ExecutEPSS 7.2%CVE-2020-1216—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code ExecutEPSS 7.2%CVE-2020-1260—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code ExecutEPSS 7.2%CVE-2019-1063—A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory CorEPSS 7.2%CVE-2018-8438—A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly validate input from a privEPSS 7.2%CVE-2024-38080HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 7.1%KEVCVE-2019-0833—An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka 'Microsoft Edge Information DisEPSS 7.1%CVE-2020-1577HIGHDirectWrite Information Disclosure VulnerabilityEPSS 7.1%CVE-2020-1230—A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code ExecutEPSS 7.1%CVE-2022-24521HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 7.1%KEVCVE-2019-1104—A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory CorrEPSS 7.1%CVE-2018-8596—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows EPSS 7.1%CVE-2019-1374—An information disclosure vulnerability exists in the way Windows Error Reporting (WER) handles objects in memory, aka 'Windows Error ReportEPSS 7.1%