Vulnerabilidades en microsoft
9312 resultadosAnálisis Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2020-1289—A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SEPSS 1.5%CVE-2019-1375—A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web reqEPSS 1.5%CVE-2020-16901MEDIUMWindows Kernel Information Disclosure VulnerabilityEPSS 1.5%CVE-2020-17046MEDIUMWindows Error Reporting Denial of Service VulnerabilityEPSS 1.5%CVE-2023-33143HIGHMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2023-35303HIGHUSB Audio Class System Driver Remote Code Execution VulnerabilityEPSS 1.5%CVE-2020-0717—An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information DisEPSS 1.5%CVE-2020-0716—An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information DisEPSS 1.5%CVE-2020-0658—An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects EPSS 1.5%CVE-2020-0705—An information disclosure vulnerability exists when the Windows Network Driver Interface Specification (NDIS) improperly handles memory.To eEPSS 1.5%CVE-2021-42297MEDIUMWindows 10 Update Assistant Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2020-0736—An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel InformationEPSS 1.5%CVE-2020-0698—An information disclosure vulnerability exists when the Telephony Service improperly discloses the contents of its memory, aka 'Windows InfoEPSS 1.5%CVE-2022-35743HIGHMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-35767HIGHWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-35766HIGHWindows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulnerabilityEPSS 1.5%CVE-2019-1381—An information disclosure vulnerability exists when the Windows Servicing Stack allows access to unprivileged file locations, aka 'MicrosoftEPSS 1.5%CVE-2025-47954HIGHMicrosoft SQL Server Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2020-17147HIGHDynamics CRM Webclient Cross-site Scripting VulnerabilityEPSS 1.5%CVE-2022-21929LOWMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.5%