Skip to content
COOEY

FAIL › dossier

Microsoft

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 40%

Microsoft is a public technology giant with a heavy security footprint, but its internal failure history reveals a critical track record of repeated RCE and privilege escalation vulnerabilities across Windows, Office, and cloud services. Recent breaches via Entra SSO and critical flaws in Defender and Exchange indicate significant risks for DIB/CMMC environments.

PROFILE
CategoryTechnology VendorWhat they doMicrosoft Corporation develops and supports software, services, devices, and solutions worldwide, including the Microsoft 365 productivity suite, Windows operating system, and Azure cloud platform.OwnershipPublic Websitehttps://www.microsoft.com ↗
SECURITY POSTURE

Microsoft maintains a high volume of critical and high-severity vulnerabilities across its product portfolio, with a pattern of repeated RCE and privilege escalation flaws in core products like Windows, Exchange, and Defender. Recent incidents include a ShinyHunters breach via Microsoft Entra SSO, indicating significant SSO and authentication control weaknesses.

Notable failures
  • ShinyHunters breach via Microsoft Entra SSO (Jan 2026)
  • CVE-2026-33825: Defender local privilege escalation (Apr 2026)
  • CVE-2026-45659: SharePoint RCE via deserialization (Jul 2026)
  • CVE-2026-13781: Chrome sandbox escape (Jun 2026)
  • CVE-2026-57983: Edge Chromium privilege bypass (Jul 2026)
  • CVE-2026-41106: M365 Copilot open redirect (Jul 2026)
Patterns: Repeated RCE in Office/Exchange/SharePoint; Privilege escalation via unpatched Windows components; SSO/Authentication bypasses (Entra); Browser sandbox escape vulnerabilities
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-04-06 CVE-2017-0148 critical Microsoft's SMBv1 server vulnerability (CVE-2017-0148) allowed remote code execution and was actively exploited, often linked to ransomware attacks, demonstrating a critical failure to secure legacy protocols and data transfers.
2022-03-25 CVE-2017-0146 critical A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk.
2022-02-15 CVE-2018-8174 critical A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution.
2022-02-10 CVE-2017-0144 critical Microsoft's SMBv1 vulnerability (CVE-2017-0144) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.
2022-02-10 CVE-2017-0145 critical Microsoft's SMBv1 vulnerability (CVE-2017-0145) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.
2021-11-03 CVE-2017-0199 critical A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks.
2021-11-03 CVE-2019-0604 critical Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.
2021-11-03 CVE-2021-40444 critical A Microsoft MSHTML vulnerability allowed for remote code execution and was actively exploited, potentially linked to ransomware attacks.
2021-11-03 CVE-2017-0143 critical A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.
2021-11-03 CVE-2021-1675 critical A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution.
2021-11-03 CVE-2017-11882 critical A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks.
2021-11-03 CVE-2019-0708 critical BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.
2021-11-03 CVE-2020-1472 critical Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments.
2023-01-10 CVE-2023-21674 high Microsoft Windows ALPC flaw exploited in wild for privilege escalation
2022-09-14 CVE-2022-37969 high Microsoft Windows CLFS Driver allows unauthorized escalation of privileges
2026-05-20 CVE-2010-0806 high Microsoft Internet Explorer use-after-free vulnerability enables remote code execution on EoL browsers.
2026-04-22 CVE-2026-33825 critical Microsoft Defender allows local privilege escalation via insufficient access control granularity, enabling ransomware-linked attackers to bypass security controls.
2026-04-14 CVE-2009-0238 high Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file.
2026-04-13 CVE-2025-60710 high Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access.
2026-03-18 CVE-2026-20963 high Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited.
2025-07-22 CVE-2025-49704 critical Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors.
2025-07-20 CVE-2025-53770 critical Microsoft SharePoint on-premises suffered a deserialization of untrusted data vulnerability allowing remote code execution, actively exploited in the wild and linked to ransomware.
2025-04-08 CVE-2025-29824 critical A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware.
2025-03-03 CVE-2018-8639 critical A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks.
2024-11-12 CVE-2024-49039 critical An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls.
2024-10-22 CVE-2024-38094 critical Microsoft SharePoint's deserialization flaw allowed remote code execution and was actively exploited by ransomware actors.
2024-10-15 CVE-2024-30088 critical A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild.
2024-06-13 CVE-2024-26169 critical A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild.
2024-05-14 CVE-2024-30051 critical A privilege escalation flaw in Microsoft's DWM Core Library lets attackers gain SYSTEM privileges and has been actively exploited in the wild.
2024-04-30 CVE-2024-29988 high Microsoft SmartScreen Prompt bypassed Mark of the Web, enabling remote code execution when chained with two other CVEs.
2024-04-23 CVE-2022-38028 high Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file.
2024-03-26 CVE-2023-24955 critical An authenticated attacker with Site Owner privileges could remotely execute code via a code injection vulnerability in Microsoft SharePoint Server.
2024-03-04 CVE-2024-21338 critical A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks.
2024-02-15 CVE-2024-21410 high Microsoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry.
2024-02-13 CVE-2024-21412 critical An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware.
2024-01-10 CVE-2023-29357 critical An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks.
2023-04-11 CVE-2023-28252 critical An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
2023-04-07 CVE-2019-1388 critical An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns.
2023-03-14 CVE-2023-24880 critical An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file.
2023-02-14 CVE-2023-23376 critical An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
2023-01-10 CVE-2022-41080 critical Microsoft Exchange Server privilege escalation vulnerability (CVE-2022-41080) chainable with RCE CVE-2022-41082 enables full system compromise.
2022-12-13 CVE-2022-44698 critical A bypass vulnerability in Microsoft Defender SmartScreen allowed attackers to evade Mark of the Web protections via a crafted malicious file.
2022-11-08 CVE-2022-41073 critical An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments.
2022-11-08 CVE-2022-41091 critical An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code.
2022-09-30 CVE-2022-41040 critical Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks.
2022-09-30 CVE-2022-41082 critical Microsoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040.
2022-06-14 CVE-2022-30190 critical An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word.
2022-05-25 CVE-2014-4148 high A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild.
2022-05-25 CVE-2015-1671 high A remote code execution flaw in Windows TrueType font handling was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems.
2022-05-25 CVE-2016-0034 critical Microsoft Silverlight's remote code execution vulnerability was actively exploited in the wild and linked to ransomware attacks.
2022-05-25 CVE-2013-0074 critical A double dereference vulnerability in Microsoft Silverlight allowed remote attackers to execute code via crafted HTML objects.
2022-05-23 CVE-2020-0638 critical A Microsoft component, Update Notification Manager, had a privilege escalation vulnerability actively exploited in ransomware attacks, allowing attackers to gain elevated system access.
2022-03-28 CVE-2018-8406 critical A Microsoft DirectX Graphics Kernel vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB systems relying on DirectX drivers.
2022-03-15 CVE-2018-8120 critical A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows systems widely used in the DIB.
2022-03-15 CVE-2015-2546 critical A Microsoft Win32k vulnerability allowed local privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows OS and Server deployments.
2022-03-03 CVE-2018-8581 critical Microsoft Exchange Server vulnerabilities allowed attackers to impersonate users, linked to ransomware activity and actively exploited in the wild.
2022-01-21 CVE-2018-8453 critical A Microsoft Win32k vulnerability allowed privilege escalation and was actively exploited, likely in ransomware attacks, impacting Windows systems widely used in the DIB.
2021-11-03 CVE-2021-36942 critical A Microsoft Windows vulnerability allowed attackers to spoof the Local Security Authority and force domain controllers to authenticate against malicious servers using NTLM.
2025-07-22 CVE-2025-49706 critical Microsoft SharePoint's improper authentication flaw allowed attackers to spoof network requests, view sensitive data, and modify information.
2025-03-11 CVE-2025-26633 critical An unpatched MMC vulnerability in Windows allows local attackers to bypass security features, and it is actively exploited in the wild.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
handled well
synthesissevere-fallout-0.70
Widespread acknowledgement of a significant vulnerability, with minimal positive commentary.
synthesissevere-fallout-0.80
Microsoft's vulnerability in the Enhanced Cryptographic Provider was widely flagged by NVD and CISA, indicating critical security failure with no praise for handling.
synthesissevere-fallout-0.80
Critical vulnerability in Microsoft's cryptographic provider enabling privilege escalation, flagged by NIST as a high-severity issue requiring immediate remediation.
synthesissevere-fallout-0.70
Widespread condemnation and association with a major global event.
synthesissevere-fallout-0.70
Significant concern and potential for reputational damage due to a kernel-level privilege escalation vulnerability.
synthesissevere-fallout-0.80
Critical security flaw in core Windows infrastructure
synthesissevere-fallout-0.80
Critical vulnerability in Windows Media Center poses significant remote code execution risk, requiring immediate patching and user awareness.
synthesissevere-fallout-0.80
Critical vulnerability in MSHTML platform poses significant remote code execution risk, requiring immediate patching and user awareness.
synthesissevere-fallout-0.80
Critical security flaw in Windows Installer enabling privilege escalation via symbolic link processing, allowing attackers to bypass file access restrictions.
synthesissevere-fallout-0.60
handled well
synthesissevere-fallout-0.70
Significant negative reception due to unspecified vulnerability and potential privilege escalation.
synthesissevere-fallout-0.70
Widespread acknowledgement of a significant vulnerability, with no positive commentary.
synthesissevere-fallout-0.80
Widespread acknowledgement of a significant vulnerability with potential for exploitation.
synthesissevere-fallout-0.70
Widespread acknowledgement of a significant security issue, coupled with a focus on the sheer volume of vulnerabilities needing remediation, suggests a negative perception of Microsoft's security post
synthesissevere-fallout-0.80
Critical vulnerability in widely used browsers poses significant security risk to enterprise environments.
synthesissevere-fallout-0.70
synthesissevere-fallout-0.80
Critical kernel vulnerability with high risk of information disclosure
synthesissevere-fallout-0.80
Microsoft's kernel vulnerability CVE-2021-33771 was flagged as critical by NVD and CISA, ranking Microsoft 5th in recentbreaches.com breach exposure metrics, indicating significant security fallout.
synthesissevere-fallout-0.80
Microsoft Win3k vulnerability (CVE-2016-0167) is flagged as critical and exploited, indicating severe security posture failure.
synthesissevere-fallout-0.70
synthesissevere-fallout-0.80
Microsoft acknowledged the vulnerability but the inclusion in CISA KEV indicates active exploitation and high risk, reflecting significant security failure.
synthesissevere-fallout-0.60
widely condemned
synthesissevere-fallout-0.60
widely condemned
synthesisnegative-0.50
Vulnerability disclosed but no specific condemnation noted in provided source
synthesissevere-fallout-0.60
handled well
synthesissevere-fallout-0.80
Widespread condemnation due to exploitation and age of vulnerability.
synthesissevere-fallout-0.80
Critical vulnerability in Azure VM Management Extensions allowing remote code execution, requiring immediate patching and user notification.
synthesissevere-fallout-0.80
Microsoft's DWM vulnerability represents a critical security failure with significant implications for enterprise systems.
synthesisnegative-0.60
Acknowledged vulnerability, but no strong condemnation.
FEDRAMP CATALOG PRODUCTS · 4
Open questions: Impact of CVE-2026-13781/13780/13776/13775/13782 on DIB systems · Frequency of patching for CVE-2026-33825 and CVE-2026-41106
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 13:55:47.564311+00:00