Exposición de Microsoft Excel

Editors
26
score de exposición
124
sitios usan
1
en explotación
0
críticos
Análisis Vexday

Com apenas 39 CVEs catalogadas, o Microsoft Excel apresenta volume relativamente contido de vulnerabilidades, mas sua taxa de exploração ativa está significativamente acima da média geral do catálogo — 5,7 vezes superior —, o que indica que as falhas historicamente identificadas nesta tecnologia tendem a ser aproveitadas na prática com frequência desproporcional. A CVE-2019-1297, a vulnerabilidade mais perigosa atualmente em exploração ativa, registra EPSS de 0,2046, sinalizando probabilidade não negligenciável de exploração observada em ambientes reais. O maior EPSS registrado entre as CVEs do produto chega a 0,28178, reforçando que ao menos parte do portfólio de vulnerabilidades continua relevante do ponto de vista operacional, mesmo sem registros de novas ocorrências nos últimos 90 dias. Equipes de segurança devem priorizar a verificação do status de correção das vulnerabilidades em KEV, dado o padrão histórico de exploração ativa acima da média.

CVEs

39 resultados
CVE-2018-8636A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 16.2%CVE-2018-8597A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "EPSS 16.1%CVE-2020-0759A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 15.2%CVE-2019-0828A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 13.7%CVE-2019-1327A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 13.5%CVE-2019-1110A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 13.2%CVE-2019-1111A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 13.2%CVE-2018-8429An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel InEPSS 12.3%CVE-2018-8382An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel InEPSS 12.3%CVE-2020-0901A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 11.6%CVE-2020-0906A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'EPSS 11.3%CVE-2020-0760A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote CEPSS 8.6%CVE-2019-1446An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 8.4%CVE-2018-8627An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, whiEPSS 8.2%CVE-2019-1464An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 8.1%CVE-2019-1263An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 7.8%CVE-2019-0669An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel InEPSS 6.4%CVE-2018-8598An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel InEPSS 6.2%CVE-2018-0907Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016, Microsoft Office 2016 Click-to-Run and MEPSS 6.0%