imPC@ndo EN

Vulnerabilità Microsoft

15.257 CVE

CVE-2021-31166
Sfruttata Critica 9.8

HTTP Protocol Stack Remote Code Execution Vulnerability

microsoft windows_10_2004 · microsoft windows_10_20h2 · microsoft windows_server_2004 · microsoft windows_server_20h2
1.00EPSS
CVE-2023-29357
Ransomware Critica 9.8

Microsoft SharePoint Server Elevation of Privilege Vulnerability

microsoft sharepoint_server
1.00EPSS
CVE-2020-1472
Ransomware Media 5.5

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · microsoft windows_server_1903 · e altri 11
1.00EPSS
CVE-2022-30190
Ransomware Alta 7.8

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 12
0.99EPSS
CVE-2017-0148
Ransomware Alta 8.1

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar…

microsoft server_message_block · siemens acuson_p300_firmware · siemens acuson_p500_firmware · siemens acuson_sc2000_firmware · e altri 5
0.99EPSS
CVE-2017-0144
Ransomware Alta 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar…

microsoft server_message_block · siemens acuson_p300_firmware · siemens acuson_p500_firmware · siemens acuson_sc2000_firmware · e altri 5
0.99EPSS
CVE-2020-0646
Sfruttata Critica 9.8

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

microsoft .net_framework
0.99EPSS
CVE-2020-0618
Sfruttata Alta 8.8

A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

microsoft sql_server
0.99EPSS
CVE-2023-36884
Ransomware Alta 7.5

Windows Search Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.99EPSS
CVE-2008-4250
Sfruttata Critica 9.8

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canoni…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.99EPSS
CVE-2024-29059
Sfruttata Alta 7.5

.NET Framework Information Disclosure Vulnerability

microsoft .net_framework
0.99EPSS
CVE-2021-33766
Sfruttata Alta 7.3

Microsoft Exchange Server Information Disclosure Vulnerability

microsoft exchange_server
0.98EPSS
CVE-2021-40444
Ransomware Alta 8.8

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An at…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 13
0.97EPSS
CVE-2023-23397
Sfruttata Critica 9.8

Microsoft Outlook Elevation of Privilege Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel · microsoft outlook
0.97EPSS
CVE-2010-3962
Sfruttata Alta 8.1

Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Unin…

microsoft internet_explorer
0.96EPSS
CVE-2015-0313
Sfruttata Critica 9.8

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil…

adobe flash_player · microsoft edge · microsoft internet_explorer · opensuse evergreen · e altri 3
0.96EPSS
CVE-2024-21412
Ransomware Alta 8.1

Internet Shortcut Files Security Feature Bypass Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_21h2 · e altri 5
0.95EPSS
CVE-2014-6332
Sfruttata Alta 8.8

OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary co…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 5
0.95EPSS
CVE-2024-21413
Sfruttata Critica 9.8

Microsoft Outlook Remote Code Execution Vulnerability

microsoft 365_apps · microsoft office_2016 · microsoft office_2019 · microsoft office_long_term_servicing_channel
0.95EPSS
CVE-2020-1147
Sfruttata Alta 7.8

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulner…

microsoft .net_core · microsoft .net_framework · microsoft sharepoint_enterprise_server · microsoft sharepoint_server · e altri 2
0.94EPSS
CVE-2021-26857
Ransomware Alta 7.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.94EPSS
CVE-2016-0189
Sfruttata Alta 7.5

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scr…

microsoft internet_explorer · microsoft jscript · microsoft vbscript
0.94EPSS
CVE-2017-0143
Ransomware Alta 8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar…

microsoft server_message_block · philips intellispace_portal · siemens acuson_p300_firmware · siemens acuson_p500_firmware · e altri 6
0.93EPSS
CVE-2015-1641
Sfruttata Alta 7.8

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 al…

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft outlook · e altri 2
0.93EPSS
CVE-2010-0249
Sfruttata Alta 8.8

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers …

microsoft internet_explorer
0.92EPSS