Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2020-1028HIGHMedia Foundation Memory Corruption VulnerabilityEPSS 3.8%CVE-2024-43630HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 3.8%CVE-2019-0732—A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handlEPSS 3.8%CVE-2020-1315—An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer InformatiEPSS 3.8%CVE-2020-1242—An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge InformationEPSS 3.8%CVE-2021-1691HIGHWindows Hyper-V Denial of Service VulnerabilityEPSS 3.8%CVE-2019-1188HIGHLNK Remote Code Execution VulnerabilityEPSS 3.8%CVE-2021-1665HIGHGDI+ Remote Code Execution VulnerabilityEPSS 3.8%CVE-2020-1307—An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel ElevaEPSS 3.8%CVE-2020-1046—.NET Framework Remote Code Execution VulnerabilityEPSS 3.8%CVE-2022-23271MEDIUMMicrosoft Dynamics GP Elevation Of Privilege VulnerabilityEPSS 3.8%CVE-2020-1012HIGHWinINet API Elevation of Privilege VulnerabilityEPSS 3.7%CVE-2021-30617—Chromium: CVE-2021-30617 Policy bypass in BlinkEPSS 3.7%CVE-2022-21986HIGH.NET Denial of Service VulnerabilityEPSS 3.7%CVE-2024-38059HIGHWin32k Elevation of Privilege VulnerabilityEPSS 3.7%CVE-2020-0728—An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules InstaEPSS 3.7%CVE-2023-38144HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 3.7%CVE-2021-42284MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 3.7%CVE-2024-38141HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 3.7%CVE-2020-1023—Microsoft SharePoint Remote Code Execution VulnerabilityEPSS 3.7%