FAIL › dossier
Microsoft
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 40%
Microsoft is a public technology giant with a heavy security footprint, but its internal failure history reveals a critical track record of repeated RCE and privilege escalation vulnerabilities across Windows, Office, and cloud services. Recent breaches via Entra SSO and critical flaws in Defender and Exchange indicate significant risks for DIB/CMMC environments.
Microsoft maintains a high volume of critical and high-severity vulnerabilities across its product portfolio, with a pattern of repeated RCE and privilege escalation flaws in core products like Windows, Exchange, and Defender. Recent incidents include a ShinyHunters breach via Microsoft Entra SSO, indicating significant SSO and authentication control weaknesses.
- ShinyHunters breach via Microsoft Entra SSO (Jan 2026)
- CVE-2026-33825: Defender local privilege escalation (Apr 2026)
- CVE-2026-45659: SharePoint RCE via deserialization (Jul 2026)
- CVE-2026-13781: Chrome sandbox escape (Jun 2026)
- CVE-2026-57983: Edge Chromium privilege bypass (Jul 2026)
- CVE-2026-41106: M365 Copilot open redirect (Jul 2026)
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-06 | CVE-2017-0148 | critical | Microsoft's SMBv1 server vulnerability (CVE-2017-0148) allowed remote code execution and was actively exploited, often linked to ransomware attacks, demonstrating a critical failure to secure legacy protocols and data transfers. |
| 2022-03-25 | CVE-2017-0146 | critical | A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk. |
| 2022-02-15 | CVE-2018-8174 | critical | A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution. |
| 2022-02-10 | CVE-2017-0144 | critical | Microsoft's SMBv1 vulnerability (CVE-2017-0144) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing. |
| 2022-02-10 | CVE-2017-0145 | critical | Microsoft's SMBv1 vulnerability (CVE-2017-0145) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing. |
| 2021-11-03 | CVE-2019-0604 | critical | Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity. |
| 2021-11-03 | CVE-2017-0199 | critical | A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks. |
| 2021-11-03 | CVE-2021-40444 | critical | A Microsoft MSHTML vulnerability allowed for remote code execution and was actively exploited, potentially linked to ransomware attacks. |
| 2021-11-03 | CVE-2017-0143 | critical | A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions. |
| 2021-11-03 | CVE-2017-11882 | critical | A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks. |
| 2021-11-03 | CVE-2021-1675 | critical | A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution. |
| 2021-11-03 | CVE-2019-0708 | critical | BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks. |
| 2021-11-03 | CVE-2020-1472 | critical | Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments. |
| 2023-01-10 | CVE-2023-21674 | high | Microsoft Windows ALPC flaw exploited in wild for privilege escalation |
| 2022-09-14 | CVE-2022-37969 | high | Microsoft Windows CLFS Driver allows unauthorized escalation of privileges |
| 2026-08-18 | CVE-2026-33824 | high | A double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions allows remote code execution and is actively exploited in the wild. |
| 2026-05-20 | CVE-2010-0806 | high | Microsoft Internet Explorer use-after-free vulnerability enables remote code execution on EoL browsers. |
| 2026-04-22 | CVE-2026-33825 | critical | Microsoft Defender allows local privilege escalation via insufficient access control granularity, enabling ransomware-linked attackers to bypass security controls. |
| 2026-04-14 | CVE-2009-0238 | high | Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file. |
| 2026-04-13 | CVE-2025-60710 | high | Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access. |
| 2026-03-18 | CVE-2026-20963 | high | Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited. |
| 2025-07-22 | CVE-2025-49704 | critical | Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors. |
| 2025-07-20 | CVE-2025-53770 | critical | Microsoft SharePoint on-premises suffered a deserialization of untrusted data vulnerability allowing remote code execution, actively exploited in the wild and linked to ransomware. |
| 2025-04-08 | CVE-2025-29824 | critical | A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware. |
| 2025-03-03 | CVE-2018-8639 | critical | A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks. |
| 2024-11-12 | CVE-2024-49039 | critical | An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls. |
| 2024-10-22 | CVE-2024-38094 | critical | Microsoft SharePoint's deserialization flaw allowed remote code execution and was actively exploited by ransomware actors. |
| 2024-10-15 | CVE-2024-30088 | critical | A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild. |
| 2024-06-13 | CVE-2024-26169 | critical | A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild. |
| 2024-05-14 | CVE-2024-30051 | critical | A privilege escalation flaw in Microsoft's DWM Core Library lets attackers gain SYSTEM privileges and has been actively exploited in the wild. |
| 2024-04-30 | CVE-2024-29988 | high | Microsoft SmartScreen Prompt bypassed Mark of the Web, enabling remote code execution when chained with two other CVEs. |
| 2024-04-23 | CVE-2022-38028 | high | Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file. |
| 2024-03-26 | CVE-2023-24955 | critical | An authenticated attacker with Site Owner privileges could remotely execute code via a code injection vulnerability in Microsoft SharePoint Server. |
| 2024-03-04 | CVE-2024-21338 | critical | A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks. |
| 2024-02-15 | CVE-2024-21410 | high | Microsoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry. |
| 2024-02-13 | CVE-2024-21412 | critical | An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware. |
| 2024-01-10 | CVE-2023-29357 | critical | An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks. |
| 2023-04-11 | CVE-2023-28252 | critical | An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks. |
| 2023-04-07 | CVE-2019-1388 | critical | An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns. |
| 2023-03-14 | CVE-2023-24880 | critical | An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file. |
| 2023-02-14 | CVE-2023-23376 | critical | An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks. |
| 2023-01-10 | CVE-2022-41080 | critical | Microsoft Exchange Server privilege escalation vulnerability (CVE-2022-41080) chainable with RCE CVE-2022-41082 enables full system compromise. |
| 2022-12-13 | CVE-2022-44698 | critical | A bypass vulnerability in Microsoft Defender SmartScreen allowed attackers to evade Mark of the Web protections via a crafted malicious file. |
| 2022-11-08 | CVE-2022-41073 | critical | An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments. |
| 2022-11-08 | CVE-2022-41091 | critical | An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code. |
| 2022-09-30 | CVE-2022-41040 | critical | Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks. |
| 2022-09-30 | CVE-2022-41082 | critical | Microsoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040. |
| 2022-06-14 | CVE-2022-30190 | critical | An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word. |
| 2022-05-25 | CVE-2014-4148 | high | A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild. |
| 2022-05-25 | CVE-2015-1671 | high | A remote code execution flaw in Windows TrueType font handling was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems. |
| 2022-05-25 | CVE-2016-0034 | critical | Microsoft Silverlight's remote code execution vulnerability was actively exploited in the wild and linked to ransomware attacks. |
| 2022-05-25 | CVE-2013-0074 | critical | A double dereference vulnerability in Microsoft Silverlight allowed remote attackers to execute code via crafted HTML objects. |
| 2022-04-06 | CVE-2021-31166 | high | Microsoft's http.sys HTTP protocol stack contained a remote code execution vulnerability that was actively exploited in the wild. |
| 2022-03-25 | CVE-2014-6332 | high | A 2014 OLE automation array RCE in Windows was actively exploited in the wild and remains in CISA's KEV catalog. |
| 2022-03-25 | CVE-2014-6324 | high | Microsoft KDC allows remote authenticated users to escalate to domain admin via privilege escalation. |
| 2022-03-03 | CVE-2010-3333 | high | A stack-based buffer overflow in Microsoft Office's RTF parser allowed remote code execution, and it was actively exploited in the wild. |
| 2022-03-03 | CVE-2012-1856 | high | A 12-year-old unpatched Microsoft Office ActiveX vulnerability in MSCOMCTL.OCX allows remote attackers to execute arbitrary code via crafted documents or web pages. |
| 2022-03-03 | CVE-2017-8540 | high | A memory corruption flaw in Microsoft's Malware Protection Engine allowed remote code execution when scanning specially crafted files. |
| 2022-03-03 | CVE-2009-1123 | high | A 2009 Windows kernel privilege escalation flaw was actively exploited in the wild for years before patching. |
| 2022-03-03 | CVE-2009-3129 | high | A remote code execution vulnerability in Microsoft Excel allows attackers to execute arbitrary code via a malicious spreadsheet file. |
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Azure Commercial Cloud | Authorized | High |
| Azure Government (includes Dynamics 365) | Authorized | High |
| Microsoft Office 365 GCC High | In Process | High |
| Office 365 Multi-Tenant & Supporting Services | Authorized | Moderate |
- MICROSOFT CORP (MSFT, US5949181045) - Company Profile · financialdata.net
- Microsoft (MSFT) Company Profile & Description - Stock Analysis · stockanalysis.com
- Microsoft Patches Teams Vulnerability: Critical Fix Against Remote Code ... · dailysecurityreview.com
- Microsoft Windows Security Vulnerabilities in 2026 · stack.watch
- ShinyHunters Allegedly Breach Panera Bread and Other Companies via ... · dailysecurityreview.com
- Microsoft CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find · www.cvefind.com
- CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io