Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2018-8453HIGHAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k EPSS 70.0%KEVCVE-2023-38171HIGHMicrosoft QUIC Denial of Service VulnerabilityEPSS 69.7%CVE-2019-0568—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 69.5%CVE-2020-1181—A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net webEPSS 69.3%CVE-2018-8467—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 69.0%CVE-2018-8466—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 69.0%CVE-2018-8291—A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "ScriptingEPSS 69.0%CVE-2018-8288—A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "ScriptingEPSS 69.0%CVE-2020-0938HIGHA remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a speciallyEPSS 69.0%KEVCVE-2025-9491MEDIUMMicrosoft Windows LNK File UI Misrepresentation Remote Code Execution VulnerabilityEPSS 68.9%CVE-2019-0626—A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP serveEPSS 68.6%CVE-2018-8631—A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory CorEPSS 68.5%CVE-2018-8355—A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "ScriptingEPSS 68.2%CVE-2024-30088HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 68.2%KEVCVE-2019-1166—A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (MessageEPSS 68.1%CVE-2018-8397—A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 67.9%CVE-2022-34713HIGHMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityEPSS 67.8%KEVCVE-2020-0610—A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to theEPSS 67.6%CVE-2022-41034HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 67.5%CVE-2023-24950MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 67.5%