Exposición de Windows Server

Operating systems
1483
score de exposición
243.602
sitios usan
33
en explotación
3
críticos
Análisis Vexday

Windows Server acumula 831 CVEs catalogadas, das quais 33 estão confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 8,8 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada. A CVE mais perigosa em atividade, CVE-2019-0708, registra EPSS de 1,0, sinalizando probabilidade máxima de exploração e exigindo atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O tipo de falha mais recorrente é CWE-59 (improper link resolution before file access, ou "link following"), sugerindo que controles de integridade de sistema de arquivos e privilégios de acesso devem compor a linha de defesa prioritária. Embora nenhuma CVE nova tenha surgido nos últimos 90 dias, o perfil histórico da plataforma — com 3 falhas críticas ativas e EPSS máximo observado de 0,99999 — reforça a necessidade de gestão contínua e rigorosa de patches.

CVEs

831 resultados
CVE-2020-0669An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation oEPSS 1.3%CVE-2020-1016An information disclosure vulnerability exists when the Windows Push Notification Service improperly handles objects in memory, aka 'WindowsEPSS 1.3%CVE-2019-9510MEDIUMMicrosoft Windows RDP can bypass the Windows lock screenEPSS 1.3%CVE-2020-0820An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation InformationEPSS 1.3%CVE-2020-1296A vulnerability exists in the way the Windows Diagnostics & feedback settings app handles objects in memory, aka 'Windows Diagnostics & EPSS 1.3%CVE-2019-1368A security feature bypass exists when Windows Secure Boot improperly restricts access to debugging functionality, aka 'Windows Secure Boot SEPSS 1.3%CVE-2019-1274An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel InEPSS 1.2%CVE-2019-1282An information disclosure exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle sandbox checks, aka 'WEPSS 1.2%CVE-2019-1254An information disclosure vulnerability exists when Windows Hyper-V writes uninitialized memory to disk, aka 'Windows Hyper-V Information DiEPSS 1.2%CVE-2019-0775An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel InformationEPSS 1.2%CVE-2020-1070An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file systemEPSS 1.2%CVE-2019-1391A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. TEPSS 1.2%CVE-2020-0634An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aEPSS 1.2%CVE-2019-1339An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error ReportEPSS 1.2%CVE-2020-1420An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerabilityEPSS 1.2%CVE-2020-1358An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory.To exploit this vulnerabEPSS 1.2%CVE-2020-1361An information disclosure vulnerability exists in the way that the WalletService handles memory.To exploit the vulnerability, an attacker woEPSS 1.2%CVE-2020-1330An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'WiEPSS 1.2%CVE-2020-1367An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel InformationEPSS 1.2%CVE-2020-1072An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel InformationEPSS 1.2%

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →