Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2021-36934HIGHWindows Elevation of Privilege VulnerabilityEPSS 67.3%KEVCVE-2023-36606HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 67.2%CVE-2018-8145—An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker EPSS 67.2%CVE-2019-0618—A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka EPSS 67.0%CVE-2018-0953—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "ScriptinEPSS 66.8%CVE-2018-8139—A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "ScriptinEPSS 66.8%CVE-2024-43572HIGHMicrosoft Management Console Remote Code Execution VulnerabilityEPSS 66.7%KEVCVE-2018-0980—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 66.3%CVE-2021-36942HIGHWindows LSA Spoofing VulnerabilityEPSS 66.0%KEVCVE-2025-55315CRITICALASP.NET Security Feature Bypass VulnerabilityEPSS 65.9%CVE-2020-0655—A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated atEPSS 65.7%CVE-2023-21768HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 65.4%CVE-2020-1020HIGHA remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a speciallyEPSS 65.0%KEVCVE-2018-8476—A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory, aka "WindowsEPSS 64.8%CVE-2025-29971HIGHWeb Threat Defense (WTD.sys) Denial of Service VulnerabilityEPSS 64.4%CVE-2018-0986—A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, lEPSS 63.3%CVE-2024-43642HIGHWindows SMB Denial of Service VulnerabilityEPSS 63.1%CVE-2019-0698—A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, akaEPSS 62.8%CVE-2024-26212HIGHDHCP Server Service Denial of Service VulnerabilityEPSS 62.6%CVE-2018-8617—A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "CEPSS 62.5%