Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2023-28274HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 6.8%CVE-2024-26198HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 6.8%CVE-2019-1449—A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially crafted file, which cEPSS 6.8%CVE-2023-35388HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 6.8%CVE-2019-1470—An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authEPSS 6.8%CVE-2019-1099—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 6.8%CVE-2019-0559—An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka "Microsoft Outlook IEPSS 6.8%CVE-2021-43209HIGH3D Viewer Remote Code Execution VulnerabilityEPSS 6.8%CVE-2019-1212CRITICALWindows DHCP Server Denial of Service VulnerabilityEPSS 6.7%CVE-2019-0835—An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory, aka 'Microsoft ScriptinEPSS 6.7%CVE-2020-1375—An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of PriEPSS 6.7%CVE-2021-31974HIGHServer for NFS Denial of Service VulnerabilityEPSS 6.7%CVE-2019-1098—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 6.7%CVE-2019-1094—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 6.7%CVE-2019-1100—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 6.7%CVE-2019-1101—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 6.7%CVE-2019-1095—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 6.7%CVE-2019-1116—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 6.7%CVE-2023-36394HIGHWindows Search Service Elevation of Privilege VulnerabilityEPSS 6.7%CVE-2020-0611—A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote DeEPSS 6.7%