imPC@ndo IT

Microsoft vulnerabilities

15.347 CVE

CVE-2020-1054
Exploited High 7.8

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 13 more
0.53EPSS
CVE-2024-43461
Exploited High 8.8

Windows MSHTML Platform Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.52EPSS
CVE-2009-1537
Exploited High 8.8

Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a cr…

microsoft directx · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · and 1 more
0.51EPSS
CVE-2024-38094
Ransomware High 7.2

Microsoft SharePoint Remote Code Execution Vulnerability

microsoft sharepoint_server
0.51EPSS
CVE-2023-5217
Exploited High 8.8

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

apple ipados · apple iphone_os · debian debian_linux · fedoraproject fedora · and 7 more
0.49EPSS
CVE-2023-28252
Ransomware High 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.49EPSS
CVE-2020-16009
Exploited High 8.8

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

cefsharp cefsharp · debian debian_linux · fedoraproject fedora · google chrome · and 4 more
0.49EPSS
CVE-2006-2492
Exploited High 8.8

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 200…

microsoft office · microsoft works_suite
0.48EPSS
CVE-2011-1889
Exploited Critical 9.8

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."…

microsoft forefront_threat_management_gateway
0.48EPSS
CVE-2014-4077
Exploited High 7.8

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PD…

microsoft office_2007_ime · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · and 1 more
0.48EPSS
CVE-2014-4123
Exploited High 8.8

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.

microsoft internet_explorer
0.47EPSS
CVE-2019-0803
Exploited High 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · and 11 more
0.45EPSS
CVE-2024-29988
Exploited High 8.8

SmartScreen Prompt Security Feature Bypass Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_21h2 · and 5 more
0.45EPSS
CVE-2019-1367
Ransomware High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.

microsoft internet_explorer
0.45EPSS
CVE-2015-2425
Exploited High 8.8

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and …

microsoft internet_explorer
0.45EPSS
CVE-2015-2419
Exploited High 8.8

JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."

microsoft internet_explorer
0.45EPSS
CVE-2013-3900
Exploited Medium 5.5

Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windo…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 18 more
0.45EPSS
CVE-2024-43573
Exploited Medium 6.5

Windows MSHTML Platform Spoofing Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.44EPSS
CVE-2016-3235
Exploited High 7.8

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vuln…

microsoft visio · microsoft visio_viewer
0.43EPSS
CVE-2023-36874
Exploited High 7.8

Windows Error Reporting Service Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 8 more
0.43EPSS
CVE-2009-0238
Exploited High 8.8

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attacker…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · and 1 more
0.43EPSS
CVE-2020-0787
Ransomware High 7.8

An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · and 13 more
0.43EPSS
CVE-2007-0671
Exploited High 8.8

Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero…

microsoft access · microsoft excel · microsoft excel_viewer · microsoft frontpage · and 10 more
0.42EPSS
CVE-2023-21674
Exploited High 8.8

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.42EPSS
CVE-2022-21999
Ransomware High 7.8

Windows Print Spooler Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · and 13 more
0.42EPSS