Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2018-8444—An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requestEPSS 5.9%CVE-2020-1025—Microsoft Office Elevation of Privilege VulnerabilityEPSS 5.9%CVE-2020-0774—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 5.9%CVE-2021-40481HIGHMicrosoft Office Visio Remote Code Execution VulnerabilityEPSS 5.9%CVE-2020-16863HIGHWindows Remote Desktop Service Denial of Service VulnerabilityEPSS 5.8%CVE-2018-8238—A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, akaEPSS 5.8%CVE-2018-1037—An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compilEPSS 5.8%CVE-2019-1299—An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft EEPSS 5.8%CVE-2019-1230—An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails to properly validateEPSS 5.8%CVE-2021-42298HIGHMicrosoft Defender Remote Code Execution VulnerabilityEPSS 5.8%CVE-2019-1286—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 5.8%CVE-2019-0972MEDIUMLocal Security Authority Subsystem Service Denial of Service VulnerabilityEPSS 5.8%CVE-2024-21306MEDIUMMicrosoft Bluetooth Driver Spoofing VulnerabilityEPSS 5.8%CVE-2019-1443—An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint SEPSS 5.7%CVE-2019-0988HIGHScripting Engine Memory Corruption VulnerabilityEPSS 5.7%CVE-2018-8310—A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "EPSS 5.7%CVE-2019-0820—A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET CoEPSS 5.7%CVE-2023-33131HIGHMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 5.7%CVE-2019-0906HIGHJet Database Engine Remote Code Execution VulnerabilityEPSS 5.7%CVE-2022-23267HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 5.7%