Vulnerabilidades em microsoft
10.810 resultadosAnálise Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2024-30035HIGHWindows DWM Core Library Elevation of Privilege VulnerabilityEPSS 3.5%CVE-2021-27058HIGHMicrosoft Office ClickToRun Remote Code Execution VulnerabilityEPSS 3.5%CVE-2021-26433HIGHWindows Services for NFS ONCRPC XDR Driver Information Disclosure VulnerabilityEPSS 3.5%CVE-2018-8247—An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requestEPSS 3.5%CVE-2023-21552HIGHWindows GDI Elevation of Privilege VulnerabilityEPSS 3.5%CVE-2019-0813—An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'WindEPSS 3.5%CVE-2019-0959HIGHWindows Common Log File System Driver Elevation of Privilege VulnerabilityEPSS 3.5%CVE-2026-50509HIGHWireless Wide Area Network Service (WwanSvc) Elevation of Privilege VulnerabilityEPSS 3.5%CVE-2022-21904HIGHWindows GDI Information Disclosure VulnerabilityEPSS 3.5%CVE-2023-24892HIGHMicrosoft Edge (Chromium-based) Webview2 Spoofing VulnerabilityEPSS 3.5%CVE-2019-0985HIGHMicrosoft Speech API Remote Code Execution VulnerabilityEPSS 3.5%CVE-2019-1318—A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions, aka 'Microsoft WindEPSS 3.5%CVE-2022-26824HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 3.5%CVE-2022-26823HIGHWindows DNS Server Remote Code Execution VulnerabilityEPSS 3.5%CVE-2022-26924HIGHYARP Denial of Service VulnerabilityEPSS 3.5%CVE-2025-21181HIGHMicrosoft Message Queuing (MSMQ) Denial of Service VulnerabilityEPSS 3.5%CVE-2018-8153—A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "MicroEPSS 3.5%CVE-2020-17122HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 3.5%CVE-2026-20843HIGHWindows Routing and Remote Access Service (RRAS) Elevation of Privilege VulnerabilityEPSS 3.5%CVE-2024-38021HIGHMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 3.5%