Vulnerabilidades em microsoft

10.810 resultados
Análise Vexday

Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.

CVE-2024-43629HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 4.4%CVE-2023-28266MEDIUMWindows Common Log File System Driver Information Disclosure VulnerabilityEPSS 4.4%CVE-2018-8506—An Information Disclosure vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka "Microsoft WiEPSS 4.4%CVE-2026-59865CRITICALKiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`EPSS 4.4%CVE-2021-1696MEDIUMWindows Graphics Component Information Disclosure VulnerabilityEPSS 4.4%CVE-2022-34699HIGHWindows Win32k Elevation of Privilege VulnerabilityEPSS 4.4%CVE-2019-0731—An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows ElevationEPSS 4.4%CVE-2019-1365—An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to itEPSS 4.4%CVE-2019-0730—An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows ElevationEPSS 4.4%CVE-2020-1224MEDIUMMicrosoft Excel Information Disclosure VulnerabilityEPSS 4.4%CVE-2020-1317—An elevation of privilege vulnerability exists when Group Policy improperly checks access, aka 'Group Policy Elevation of Privilege VulnerabEPSS 4.3%CVE-2019-0649—A vulnerability exists in Microsoft Chakra JIT server, aka 'Scripting Engine Elevation of Privileged Vulnerability'.EPSS 4.3%CVE-2022-34728MEDIUMWindows Graphics Component Information Disclosure VulnerabilityEPSS 4.3%CVE-2022-22000HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 4.3%CVE-2021-27054HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 4.3%CVE-2021-27057HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 4.3%CVE-2019-1156HIGHJet Database Engine Remote Code Execution VulnerabilityEPSS 4.3%CVE-2019-1147HIGHJet Database Engine Remote Code Execution VulnerabilityEPSS 4.3%CVE-2021-28323MEDIUMWindows DNS Information Disclosure VulnerabilityEPSS 4.3%CVE-2023-33160HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 4.3%