Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2020-1382—An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows GraphiEPSS 5.4%CVE-2019-0819—An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata permissions, aEPSS 5.4%CVE-2020-16881HIGHVisual Studio JSON Remote Code Execution VulnerabilityEPSS 5.4%CVE-2018-8150—A security feature bypass vulnerability exists when the Microsoft Outlook attachment block filter does not properly handle attachments, aka EPSS 5.4%CVE-2021-26435HIGHWindows Scripting Engine Memory Corruption VulnerabilityEPSS 5.3%CVE-2019-1301—A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'.EPSS 5.3%CVE-2019-1084—An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters.EPSS 5.3%CVE-2023-21752HIGHWindows Backup Service Elevation of Privilege VulnerabilityEPSS 5.3%CVE-2018-8244—An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka "Microsoft Outlook EPSS 5.3%CVE-2018-0989—An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "ScrEPSS 5.3%CVE-2018-0892—An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information DisEPSS 5.3%CVE-2019-1313—An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, akaEPSS 5.3%CVE-2020-0801—A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory CoEPSS 5.3%CVE-2019-1206HIGHWindows DHCP Server Denial of Service VulnerabilityEPSS 5.3%CVE-2020-1433—An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF EPSS 5.3%CVE-2019-1029—Skype for Business and Lync Server Denial of Service VulnerabilityEPSS 5.3%CVE-2024-30037MEDIUMWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 5.3%CVE-2019-0804—An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent InEPSS 5.3%CVE-2024-38085HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 5.3%CVE-2020-1348—An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows EPSS 5.2%