Vulnerabilidades en microsoft
9312 resultadosAnálisis Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2023-36013MEDIUMPowerShell Information Disclosure VulnerabilityEPSS 1.4%CVE-2022-41047HIGHMicrosoft ODBC Driver Remote Code Execution VulnerabilityEPSS 1.4%CVE-2023-21549HIGHWindows SMB Witness Service Elevation of Privilege VulnerabilityEPSS 1.4%CVE-2020-17098MEDIUMWindows GDI+ Information Disclosure VulnerabilityEPSS 1.4%CVE-2024-38045HIGHWindows TCP/IP Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-49002HIGHSQL Server Native Client Remote Code Execution VulnerabilityEPSS 1.4%CVE-2019-1490—A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for BusiEPSS 1.4%CVE-2020-17094MEDIUMWindows Error Reporting Information Disclosure VulnerabilityEPSS 1.4%CVE-2024-49005HIGHSQL Server Native Client Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-49000HIGHSQL Server Native Client Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-49004HIGHSQL Server Native Client Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-49001HIGHSQL Server Native Client Remote Code Execution VulnerabilityEPSS 1.4%CVE-2020-16978MEDIUMMicrosoft Dynamics 365 (On-Premise) Cross Site Scripting VulnerabilityEPSS 1.4%CVE-2020-16956MEDIUMMicrosoft Dynamics 365 (On-Premise) Cross Site Scripting VulnerabilityEPSS 1.4%CVE-2024-49003HIGHSQL Server Native Client Remote Code Execution VulnerabilityEPSS 1.4%CVE-2022-21899MEDIUMWindows Extensible Firmware Interface Security Feature Bypass VulnerabilityEPSS 1.4%CVE-2025-59247HIGHAzure PlayFab Elevation of Privilege VulnerabilityEPSS 1.4%CVE-2020-0871—An information disclosure vulnerability exists when Windows Network Connections Service fails to properly handle objects in memory, aka 'WinEPSS 1.4%CVE-2018-8116—A denial of service vulnerability exists in the way that Windows handles objects in memory, aka "Microsoft Graphics Component Denial of ServEPSS 1.4%CVE-2020-1191—An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory, aka 'Windows EPSS 1.4%