Vulnerabilidades en microsoft
9322 resultadosAnálisis Vexday
Microsoft apresenta 41 vulnerabilidades registradas, com 29 publicadas nos últimos 90 dias, indicando ritmo elevado de descobertas recentes. Oito vulnerabilidades críticas foram identificadas, predominantemente relacionadas a traversal de diretório (CWE-22), mas nenhuma está sob exploração ativa conhecida no momento. O volume recente de falhas requer atenção contínua em patching, especialmente considerando a superfície de ataque do ecossistema Microsoft.
CVE-2023-32038HIGHMicrosoft ODBC Driver Remote Code Execution VulnerabilityEPSS 1.2%CVE-2016-9485—On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because it fails to set any permissions on downloaded file objectsEPSS 1.2%CVE-2021-38652HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.2%CVE-2020-0904MEDIUMWindows Hyper-V Denial of Service VulnerabilityEPSS 1.2%CVE-2016-9486—On Windows endpoints, the SecureConnector agent is vulnerable to privilege escalation whereby an authenticated unprivileged user can obtain administrator privileges on the endpoint because files are created in a folder with incorrect privilegesEPSS 1.2%CVE-2020-1070—An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file systemEPSS 1.2%CVE-2021-38651HIGHMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.2%CVE-2020-0886HIGHWindows Storage Services Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2025-29804HIGHVisual Studio Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2024-21326CRITICALMicrosoft Edge (Chromium-based) Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2022-37956HIGHWindows Kernel Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2020-17135MEDIUMAzure DevOps Server Spoofing VulnerabilityEPSS 1.2%CVE-2019-1391—A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. TEPSS 1.2%CVE-2021-27075MEDIUMAzure Virtual Machine Information Disclosure VulnerabilityEPSS 1.2%CVE-2021-24104MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 1.2%CVE-2018-8142—A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass VulnerabiEPSS 1.2%CVE-2022-37962HIGHMicrosoft PowerPoint Remote Code Execution VulnerabilityEPSS 1.2%CVE-2023-24900MEDIUMWindows NTLM Security Support Provider Information Disclosure VulnerabilityEPSS 1.2%CVE-2020-0634—An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aEPSS 1.2%CVE-2024-21399HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.2%