imPC@ndo IT

Microsoft vulnerabilities

15.313 CVE

CVE-2023-21529
Ransomware High 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.62EPSS
CVE-2017-0059
Exploited Medium 4.3

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CV…

microsoft internet_explorer
0.62EPSS
CVE-2012-1856
Exploited High 8.8

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 S…

microsoft commerce_server · microsoft host_integration_server · microsoft office · microsoft office_web_components · and 3 more
0.62EPSS
CVE-2024-43468
Exploited Critical 9.8

Microsoft Configuration Manager Remote Code Execution Vulnerability

microsoft configuration_manager_2403 · microsoft configuration_manager_2409 · microsoft configuration_manager_2503
0.61EPSS
CVE-2017-11774
Exploited High 7.8

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Office handles objects in memory, aka "Microsoft Outlook Security Feature Bypass Vulnerability."

microsoft outlook
0.60EPSS
CVE-2024-21338
Ransomware High 7.8

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_21h2 · and 5 more
0.60EPSS
CVE-2014-4148
Exploited High 8.8

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to ex…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 5 more
0.60EPSS
CVE-2021-33742
Exploited High 7.5

Windows MSHTML Platform Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 10 more
0.59EPSS
CVE-2025-24054
Exploited Medium 6.5

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.59EPSS
CVE-2009-0557
Exploited High 7.8

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel View…

microsoft office · microsoft office_compatibility_pack · microsoft office_excel_viewer · microsoft office_sharepoint_server · and 1 more
0.59EPSS
CVE-2016-0034
Ransomware High 8.8

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code…

microsoft silverlight
0.59EPSS
CVE-2016-7262
Exploited High 7.8

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka …

microsoft excel · microsoft excel_viewer · microsoft office_compatibility_pack
0.58EPSS
CVE-2013-7331
Exploited Medium 6.5

The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a r…

microsoft internet_explorer
0.58EPSS
CVE-2016-7193
Exploited High 7.8

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoi…

microsoft office · microsoft office_compatibility_pack · microsoft word · microsoft word_viewer
0.58EPSS
CVE-2017-0101
Ransomware High 7.8

The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allow local use…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.57EPSS
CVE-2015-1701
Ransomware High 7.8

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.56EPSS
CVE-2015-1671
Exploited High 7.8

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before…

microsoft .net_framework · microsoft live_meeting · microsoft lync · microsoft silverlight
0.55EPSS
CVE-2022-21882
Exploited High 7.0

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · and 5 more
0.55EPSS
CVE-2018-8373
Exploited High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer …

microsoft internet_explorer
0.54EPSS
CVE-2021-31196
Exploited High 7.2

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.54EPSS
CVE-2022-21971
Exploited High 7.8

Windows Runtime Remote Code Execution Vulnerability

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · and 5 more
0.54EPSS
CVE-2019-0808
Exploited High 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.

microsoft windows_7 · microsoft windows_server_2008
0.53EPSS
CVE-2015-1642
Exploited High 7.8

Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office
0.53EPSS
CVE-2019-0541
Exploited High 8.8

A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explo…

microsoft excel_viewer · microsoft internet_explorer · microsoft office · microsoft office_365_proplus · and 1 more
0.53EPSS
CVE-2012-2539
Exploited High 7.8

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, ak…

microsoft office_compatibility_pack · microsoft office_web_apps · microsoft office_word_viewer · microsoft sharepoint_server · and 1 more
0.53EPSS