FAIL › dossier
Microsoft
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 40%
Microsoft is a public technology giant with a heavy security footprint, but its internal failure history reveals a critical track record of repeated RCE and privilege escalation vulnerabilities across Windows, Office, and cloud services. Recent breaches via Entra SSO and critical flaws in Defender and Exchange indicate significant risks for DIB/CMMC environments.
Microsoft maintains a high volume of critical and high-severity vulnerabilities across its product portfolio, with a pattern of repeated RCE and privilege escalation flaws in core products like Windows, Exchange, and Defender. Recent incidents include a ShinyHunters breach via Microsoft Entra SSO, indicating significant SSO and authentication control weaknesses.
- ShinyHunters breach via Microsoft Entra SSO (Jan 2026)
- CVE-2026-33825: Defender local privilege escalation (Apr 2026)
- CVE-2026-45659: SharePoint RCE via deserialization (Jul 2026)
- CVE-2026-13781: Chrome sandbox escape (Jun 2026)
- CVE-2026-57983: Edge Chromium privilege bypass (Jul 2026)
- CVE-2026-41106: M365 Copilot open redirect (Jul 2026)
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-06 | CVE-2017-0148 | critical | Microsoft's SMBv1 server vulnerability (CVE-2017-0148) allowed remote code execution and was actively exploited, often linked to ransomware attacks, demonstrating a critical failure to secure legacy protocols and data transfers. |
| 2022-03-25 | CVE-2017-0146 | critical | A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk. |
| 2022-02-15 | CVE-2018-8174 | critical | A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution. |
| 2022-02-10 | CVE-2017-0144 | critical | Microsoft's SMBv1 vulnerability (CVE-2017-0144) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing. |
| 2022-02-10 | CVE-2017-0145 | critical | Microsoft's SMBv1 vulnerability (CVE-2017-0145) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing. |
| 2021-11-03 | CVE-2017-0199 | critical | A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks. |
| 2021-11-03 | CVE-2019-0604 | critical | Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity. |
| 2021-11-03 | CVE-2021-40444 | critical | A Microsoft MSHTML vulnerability allowed for remote code execution and was actively exploited, potentially linked to ransomware attacks. |
| 2021-11-03 | CVE-2017-0143 | critical | A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions. |
| 2021-11-03 | CVE-2021-1675 | critical | A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution. |
| 2021-11-03 | CVE-2017-11882 | critical | A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks. |
| 2021-11-03 | CVE-2019-0708 | critical | BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks. |
| 2021-11-03 | CVE-2020-1472 | critical | Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments. |
| 2023-01-10 | CVE-2023-21674 | high | Microsoft Windows ALPC flaw exploited in wild for privilege escalation |
| 2022-09-14 | CVE-2022-37969 | high | Microsoft Windows CLFS Driver allows unauthorized escalation of privileges |
| 2026-05-20 | CVE-2010-0806 | high | Microsoft Internet Explorer use-after-free vulnerability enables remote code execution on EoL browsers. |
| 2026-04-22 | CVE-2026-33825 | critical | Microsoft Defender allows local privilege escalation via insufficient access control granularity, enabling ransomware-linked attackers to bypass security controls. |
| 2026-04-14 | CVE-2009-0238 | high | Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file. |
| 2026-04-13 | CVE-2025-60710 | high | Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access. |
| 2026-03-18 | CVE-2026-20963 | high | Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited. |
| 2025-07-22 | CVE-2025-49704 | critical | Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors. |
| 2025-07-20 | CVE-2025-53770 | critical | Microsoft SharePoint on-premises suffered a deserialization of untrusted data vulnerability allowing remote code execution, actively exploited in the wild and linked to ransomware. |
| 2025-04-08 | CVE-2025-29824 | critical | A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware. |
| 2025-03-03 | CVE-2018-8639 | critical | A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks. |
| 2024-11-12 | CVE-2024-49039 | critical | An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls. |
| 2024-10-22 | CVE-2024-38094 | critical | Microsoft SharePoint's deserialization flaw allowed remote code execution and was actively exploited by ransomware actors. |
| 2024-10-15 | CVE-2024-30088 | critical | A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild. |
| 2024-06-13 | CVE-2024-26169 | critical | A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild. |
| 2024-05-14 | CVE-2024-30051 | critical | A privilege escalation flaw in Microsoft's DWM Core Library lets attackers gain SYSTEM privileges and has been actively exploited in the wild. |
| 2024-04-30 | CVE-2024-29988 | high | Microsoft SmartScreen Prompt bypassed Mark of the Web, enabling remote code execution when chained with two other CVEs. |
| 2024-04-23 | CVE-2022-38028 | high | Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file. |
| 2024-03-26 | CVE-2023-24955 | critical | An authenticated attacker with Site Owner privileges could remotely execute code via a code injection vulnerability in Microsoft SharePoint Server. |
| 2024-03-04 | CVE-2024-21338 | critical | A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks. |
| 2024-02-15 | CVE-2024-21410 | high | Microsoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry. |
| 2024-02-13 | CVE-2024-21412 | critical | An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware. |
| 2024-01-10 | CVE-2023-29357 | critical | An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks. |
| 2023-04-11 | CVE-2023-28252 | critical | An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks. |
| 2023-04-07 | CVE-2019-1388 | critical | An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns. |
| 2023-03-14 | CVE-2023-24880 | critical | An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file. |
| 2023-02-14 | CVE-2023-23376 | critical | An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks. |
| 2023-01-10 | CVE-2022-41080 | critical | Microsoft Exchange Server privilege escalation vulnerability (CVE-2022-41080) chainable with RCE CVE-2022-41082 enables full system compromise. |
| 2022-12-13 | CVE-2022-44698 | critical | A bypass vulnerability in Microsoft Defender SmartScreen allowed attackers to evade Mark of the Web protections via a crafted malicious file. |
| 2022-11-08 | CVE-2022-41073 | critical | An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments. |
| 2022-11-08 | CVE-2022-41091 | critical | An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code. |
| 2022-09-30 | CVE-2022-41040 | critical | Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks. |
| 2022-09-30 | CVE-2022-41082 | critical | Microsoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040. |
| 2022-06-14 | CVE-2022-30190 | critical | An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word. |
| 2022-05-25 | CVE-2014-4148 | high | A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild. |
| 2022-05-25 | CVE-2015-1671 | high | A remote code execution flaw in Windows TrueType font handling was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems. |
| 2022-05-25 | CVE-2016-0034 | critical | Microsoft Silverlight's remote code execution vulnerability was actively exploited in the wild and linked to ransomware attacks. |
| 2022-05-25 | CVE-2013-0074 | critical | A double dereference vulnerability in Microsoft Silverlight allowed remote attackers to execute code via crafted HTML objects. |
| 2022-05-23 | CVE-2020-0638 | critical | A Microsoft component, Update Notification Manager, had a privilege escalation vulnerability actively exploited in ransomware attacks, allowing attackers to gain elevated system access. |
| 2022-03-28 | CVE-2018-8406 | critical | A Microsoft DirectX Graphics Kernel vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on DirectX drivers. |
| 2022-03-15 | CVE-2018-8120 | critical | A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows systems widely used in the DIB. |
| 2022-03-15 | CVE-2015-2546 | critical | A Microsoft Win32k vulnerability allowed local privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows OS and Server deployments. |
| 2022-03-03 | CVE-2018-8581 | critical | Microsoft Exchange Server vulnerabilities allowed attackers to impersonate users, linked to ransomware activity and actively exploited in the wild. |
| 2022-01-21 | CVE-2018-8453 | critical | A Microsoft Win32k vulnerability allowed privilege escalation and was actively exploited, likely in ransomware attacks, impacting Windows systems widely used in the DIB. |
| 2021-11-03 | CVE-2021-36942 | critical | A Microsoft Windows vulnerability allowed attackers to spoof the Local Security Authority and force domain controllers to authenticate against malicious servers using NTLM. |
| 2025-07-22 | CVE-2025-49706 | critical | Microsoft SharePoint's improper authentication flaw allowed attackers to spoof network requests, view sensitive data, and modify information. |
| 2025-03-11 | CVE-2025-26633 | critical | An unpatched MMC vulnerability in Windows allows local attackers to bypass security features, and it is actively exploited in the wild. |
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Azure Commercial Cloud | Authorized | High |
| Azure Government (includes Dynamics 365) | Authorized | High |
| Microsoft Office 365 GCC High | In Process | High |
| Office 365 Multi-Tenant & Supporting Services | Authorized | Moderate |
- MICROSOFT CORP (MSFT, US5949181045) - Company Profile · financialdata.net
- Microsoft (MSFT) Company Profile & Description - Stock Analysis · stockanalysis.com
- Microsoft Patches Teams Vulnerability: Critical Fix Against Remote Code ... · dailysecurityreview.com
- Microsoft Windows Security Vulnerabilities in 2026 · stack.watch
- ShinyHunters Allegedly Breach Panera Bread and Other Companies via ... · dailysecurityreview.com
- Microsoft CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find · www.cvefind.com
- CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io