Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2021-40480HIGHMicrosoft Office Visio Remote Code Execution VulnerabilityEPSS 5.7%CVE-2022-29117HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 5.7%CVE-2018-8517—A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service EPSS 5.7%CVE-2024-30051HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 5.6%KEVCVE-2020-1408—A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'MicrosoEPSS 5.6%CVE-2019-1466—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 5.6%CVE-2019-1465—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 5.6%CVE-2019-1467—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 5.6%CVE-2020-0809—A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory CoEPSS 5.6%CVE-2020-0807—A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory CoEPSS 5.6%CVE-2018-8276—A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed,EPSS 5.6%CVE-2018-8126—A security feature bypass vulnerability exists when Internet Explorer fails to validate User Mode Code Integrity (UMCI) policies, aka "InterEPSS 5.6%CVE-2022-24533HIGHRemote Desktop Protocol Remote Code Execution VulnerabilityEPSS 5.6%CVE-2023-38159HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 5.6%CVE-2021-30615—Chromium: CVE-2021-30615 Cross-origin data leak in NavigationEPSS 5.6%CVE-2018-8452—An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aEPSS 5.6%CVE-2018-8558—An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the ShareEPSS 5.6%CVE-2019-0704—An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB InformationEPSS 5.6%CVE-2023-35382HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 5.6%CVE-2019-1432—An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite InformatioEPSS 5.6%