Exposición de Windows Server

Operating systems
1480
score de exposición
237.301
sitios usan
33
en explotación
3
críticos
Análisis Vexday

Windows Server acumula 831 CVEs catalogadas, das quais 33 estão confirmadas em exploração ativa no catálogo KEV da CISA — uma taxa 8,8 vezes acima da média geral do catálogo, o que indica exposição operacional significativamente elevada. A CVE mais perigosa em atividade, CVE-2019-0708, registra EPSS de 1,0, sinalizando probabilidade máxima de exploração e exigindo atenção prioritária em ambientes que ainda não aplicaram a correção correspondente. O tipo de falha mais recorrente é CWE-59 (improper link resolution before file access, ou "link following"), sugerindo que controles de integridade de sistema de arquivos e privilégios de acesso devem compor a linha de defesa prioritária. Embora nenhuma CVE nova tenha surgido nos últimos 90 dias, o perfil histórico da plataforma — com 3 falhas críticas ativas e EPSS máximo observado de 0,99999 — reforça a necessidade de gestão contínua e rigorosa de patches.

CVEs

831 resultados
CVE-2019-0795A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote CodeEPSS 21.3%CVE-2019-1127A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution VEPSS 20.6%CVE-2019-0889A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 20.2%CVE-2019-0899A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 20.2%CVE-2019-0891A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 20.2%CVE-2019-0598A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 20.1%CVE-2019-0599A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 20.1%CVE-2019-0617A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 19.6%CVE-2019-1119A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution VEPSS 19.5%CVE-2019-1359A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 19.3%CVE-2019-0902A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 19.2%CVE-2019-0595A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 19.1%CVE-2019-1280A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attaEPSS 19.0%CVE-2020-0687A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'MicrosoEPSS 18.9%CVE-2019-1250A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 18.5%CVE-2019-1243A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database EnEPSS 18.5%CVE-2019-0856A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution VulnerabiEPSS 18.4%CVE-2019-1124A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution VEPSS 18.4%CVE-2019-0842A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine RemEPSS 18.0%CVE-2019-0630A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 2.0 (SMBv2) server handles certain requests,EPSS 17.8%