Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2018-8530—A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge SecEPSS 5.5%CVE-2022-35751HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 5.5%CVE-2018-8546—A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affEPSS 5.5%CVE-2020-0813—An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker EPSS 5.5%CVE-2021-27085HIGHInternet Explorer Remote Code Execution VulnerabilityEPSS 5.4%KEVCVE-2018-8358—A security feature bypass vulnerability exists when Microsoft Edge improperly handles redirect requests, aka "Microsoft Edge Security FeaturEPSS 5.4%CVE-2022-29145HIGH.NET and Visual Studio Denial of Service VulnerabilityEPSS 5.4%CVE-2019-0643—An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge InformationEPSS 5.4%CVE-2019-0648—An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker EPSS 5.4%CVE-2020-17087HIGHWindows Kernel Local Elevation of Privilege VulnerabilityEPSS 5.4%KEVCVE-2025-55681HIGHDesktop Window Manager Elevation of Privilege VulnerabilityEPSS 5.4%CVE-2018-8113—A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mark of the Web Tagging (MOTW), aka "Internet EPSS 5.4%CVE-2019-0990MEDIUMChakra Scripting Engine Memory Corruption VulnerabilityEPSS 5.4%CVE-2019-1023MEDIUMScripting Engine Information Disclosure VulnerabilityEPSS 5.4%CVE-2024-2169HIGHImplementations of UDP application protocols are susceptible to network loops and denial of serviceEPSS 5.4%CVE-2019-1025MEDIUMWindows Denial of Service VulnerabilityEPSS 5.4%CVE-2020-0660—A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sendsEPSS 5.4%CVE-2023-29371HIGHWindows GDI Elevation of Privilege VulnerabilityEPSS 5.4%CVE-2022-34725HIGHWindows ALPC Elevation of Privilege VulnerabilityEPSS 5.4%CVE-2019-1376—An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, akaEPSS 5.4%