Vulnerabilidades em microsoft
9.364 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2024-38063CRITICALWindows TCP/IP Remote Code Execution VulnerabilityEPSS 70.6%CVE-2022-23270HIGHWindows Point-to-Point Tunneling Protocol Remote Code Execution VulnerabilityEPSS 70.3%CVE-2026-42897HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 70.3%KEVCVE-2019-1184MEDIUMWindows Elevation of Privilege VulnerabilityEPSS 70.2%CVE-2021-42278HIGHActive Directory Domain Services Elevation of Privilege VulnerabilityEPSS 70.2%KEVCVE-2018-8453HIGHAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k EPSS 70.0%KEVCVE-2018-8291—A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "ScriptingEPSS 70.0%CVE-2018-8288—A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "ScriptingEPSS 70.0%CVE-2023-38171HIGHMicrosoft QUIC Denial of Service VulnerabilityEPSS 69.5%CVE-2019-0568—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 69.5%CVE-2020-1181—A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net webEPSS 69.3%CVE-2018-8631—A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory CorEPSS 69.2%CVE-2020-0938HIGHA remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a speciallyEPSS 69.2%KEVCVE-2018-8467—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 69.0%CVE-2018-8466—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 69.0%CVE-2025-9491MEDIUMMicrosoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityEPSS 68.9%CVE-2023-36757HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 68.6%CVE-2019-0626—A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP serveEPSS 68.3%CVE-2018-8355—A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "ScriptingEPSS 68.2%CVE-2024-30088HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 68.2%KEV