Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2023-24939HIGHServer for NFS Denial of Service VulnerabilityEPSS 4.7%CVE-2026-20840HIGHWindows NTFS Remote Code Execution VulnerabilityEPSS 4.7%CVE-2018-8320—A security feature bypass vulnerability exists in DNS Global Blocklist feature, aka "Windows DNS Security Feature Bypass Vulnerability." ThiEPSS 4.7%CVE-2019-1199—Microsoft Outlook Memory Corruption VulnerabilityEPSS 4.6%CVE-2019-1200—Microsoft Outlook Remote Code Execution VulnerabilityEPSS 4.6%CVE-2020-1449—A remote code execution vulnerability exists in Microsoft Project software when the software fails to check the source markup of a file, akaEPSS 4.6%CVE-2019-1461—A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'MicroEPSS 4.6%CVE-2021-36965HIGHWindows WLAN AutoConfig Service Remote Code Execution VulnerabilityEPSS 4.6%CVE-2020-1497—Microsoft Excel Information Disclosure VulnerabilityEPSS 4.6%CVE-2020-1502—Microsoft Word Information Disclosure VulnerabilityEPSS 4.6%CVE-2021-24085MEDIUMMicrosoft Exchange Server Spoofing VulnerabilityEPSS 4.6%CVE-2019-0588—An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissionsEPSS 4.6%CVE-2021-27061HIGHHEVC Video Extensions Remote Code Execution VulnerabilityEPSS 4.6%CVE-2021-24089HIGHHEVC Video Extensions Remote Code Execution VulnerabilityEPSS 4.6%CVE-2020-17023HIGHVisual Studio JSON Remote Code Execution VulnerabilityEPSS 4.6%CVE-2019-1324—An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles IPv6 flowlabel filled in packets, aka 'WindoEPSS 4.6%CVE-2019-0647—An information disclosure vulnerability exists when Team Foundation Server does not properly handle variables marked as secret, aka "Team FoEPSS 4.6%CVE-2019-5922—Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an uEPSS 4.6%CVE-2019-5921—Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.EPSS 4.6%CVE-2022-22716MEDIUMMicrosoft Excel Information Disclosure VulnerabilityEPSS 4.6%