imPC@ndo EN

Vulnerabilità Microsoft

15.272 CVE

CVE-2019-0841
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-08…

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_10_1809 · e altri 2
0.41EPSS
CVE-2024-38178
Sfruttata Alta 7.5

Scripting Engine Memory Corruption Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.41EPSS
CVE-2020-1464
Sfruttata Alta 7.8

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass secur…

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 14
0.41EPSS
CVE-2023-29336
Sfruttata Alta 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_server_2008 · microsoft windows_server_2012 · e altri 1
0.41EPSS
CVE-2021-34448
Sfruttata Media 6.8

Scripting Engine Memory Corruption Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 10
0.40EPSS
CVE-2013-3660
Sfruttata Alta 7.8

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not proper…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2003 · e altri 4
0.40EPSS
CVE-2021-1647
Sfruttata Alta 7.8

Microsoft Defender Remote Code Execution Vulnerability

microsoft security_essentials · microsoft system_center_endpoint_protection · microsoft windows_defender
0.39EPSS
CVE-2015-2502
Sfruttata Alta 8.8

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.

microsoft internet_explorer
0.39EPSS
CVE-2015-2424
Sfruttata Alta 8.8

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Off…

microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · microsoft powerpoint · e altri 2
0.38EPSS
CVE-2023-4762
Sfruttata Alta 8.8

Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

debian debian_linux · fedoraproject fedora · google chrome · microsoft edge_chromium
0.38EPSS
CVE-2016-0099
Ransomware Alta 7.8

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows lo…

microsoft windows_10_1507 · microsoft windows_10_1511 · microsoft windows_7 · microsoft windows_8.1 · e altri 3
0.37EPSS
CVE-2020-17144
Sfruttata Alta 8.4

Microsoft Exchange Remote Code Execution Vulnerability

microsoft exchange_server
0.37EPSS
CVE-2015-2387
Sfruttata Alta 7.8

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users …

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 5
0.35EPSS
CVE-2015-1770
Sfruttata Alta 8.8

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

microsoft office
0.35EPSS
CVE-2013-5065
Sfruttata Alta 7.8

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

microsoft windows_2003_server · microsoft windows_xp
0.35EPSS
CVE-2015-0071
Sfruttata Media 6.5

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

microsoft internet_explorer
0.34EPSS
CVE-2021-42292
Sfruttata Alta 7.8

Microsoft Excel Security Feature Bypass Vulnerability

microsoft 365_apps · microsoft excel · microsoft office · microsoft office_long_term_servicing_channel
0.32EPSS
CVE-2022-4135
Sfruttata Critica 9.6

Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

google chrome · microsoft edge · microsoft edge_chromium
0.32EPSS
CVE-2011-2005
Sfruttata Alta 7.8

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Dr…

microsoft windows_server_2003 · microsoft windows_xp
0.32EPSS
CVE-2026-20963
Sfruttata Critica 9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

microsoft sharepoint_server
0.32EPSS
CVE-2025-26633
Ransomware Alta 7.0

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.30EPSS
CVE-2024-21351
Sfruttata Alta 7.6

Windows SmartScreen Security Feature Bypass Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 8
0.30EPSS
CVE-2020-0968
Sfruttata Alta 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.

microsoft internet_explorer
0.30EPSS
CVE-2019-1405
Ransomware Alta 7.8

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1709 · microsoft windows_10_1803 · e altri 11
0.30EPSS
CVE-2017-0222
Sfruttata Alta 8.8

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

microsoft internet_explorer
0.30EPSS