imPC@ndo EN

Vulnerabilità Microsoft

15.272 CVE

CVE-2026-21509
Sfruttata Alta 7.8

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel
0.72EPSS
CVE-2017-8540
Sfruttata Alta 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft endpoint_protection · microsoft exchange_server · microsoft forefront_endpoint_protection · microsoft forefront_security · e altri 5
0.72EPSS
CVE-2013-3163
Sfruttata Alta 8.8

Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013…

microsoft internet_explorer
0.71EPSS
CVE-2026-42897
Sfruttata Alta 8.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

microsoft exchange_server · microsoft exchange_server_subscription_edition
0.70EPSS
CVE-2021-42278
Ransomware Alta 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

microsoft windows_server_2004 · microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · e altri 3
0.70EPSS
CVE-2018-8453
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 20…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1703 · microsoft windows_10_1709 · e altri 11
0.70EPSS
CVE-2016-0185
Sfruttata Alta 7.8

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_8.1 · microsoft windows_vista
0.70EPSS
CVE-2013-3896
Sfruttata Media 5.5

Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka "Silverlight Vulnerability."

microsoft silverlight
0.70EPSS
CVE-2020-0938
Sfruttata Alta 7.8

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfu…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 13
0.69EPSS
CVE-2016-3393
Sfruttata Alta 7.8

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute …

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 5
0.69EPSS
CVE-2024-30088
Ransomware Alta 7.0

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.68EPSS
CVE-2022-34713
Sfruttata Alta 7.8

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 12
0.68EPSS
CVE-2009-0556
Sfruttata Alta 8.8

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers…

microsoft office_powerpoint · microsoft powerpoint
0.68EPSS
CVE-2021-36934
Sfruttata Alta 7.8

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitr…

microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · microsoft windows_10_20h2 · e altri 1
0.67EPSS
CVE-2024-43572
Sfruttata Alta 7.8

Microsoft Management Console Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.67EPSS
CVE-2021-36942
Ransomware Alta 7.5

Windows LSA Spoofing Vulnerability

microsoft windows_server_2004 · microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · e altri 2
0.66EPSS
CVE-2014-1812
Ransomware Alta 8.8

The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_server_2008 · e altri 2
0.65EPSS
CVE-2020-1020
Sfruttata Alta 8.8

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfu…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 12
0.65EPSS
CVE-2016-7256
Sfruttata Alta 8.8

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attack…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_7 · e altri 6
0.65EPSS
CVE-2017-8543
Sfruttata Critica 9.8

Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows S…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_10_1607 · microsoft windows_10_1703 · e altri 6
0.64EPSS
CVE-2026-32202
Sfruttata Media 4.3

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 10
0.64EPSS
CVE-2016-0151
Ransomware Alta 7.8

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows …

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 1
0.63EPSS
CVE-2009-0563
Sfruttata Alta 7.8

Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Of…

microsoft office · microsoft office_compatibility_pack · microsoft office_word_viewer · microsoft open_xml_file_format_converter
0.63EPSS
CVE-2026-45498
Sfruttata Media 4.0

Microsoft Defender Denial of Service Vulnerability

microsoft defender_antimalware_platform
0.63EPSS
CVE-2010-2572
Sfruttata Alta 7.8

Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."

microsoft powerpoint
0.63EPSS