Skip to content
COOEY

FAIL › dossier

Microsoft

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 40%

Microsoft is a public technology giant with a heavy security footprint, but its internal failure history reveals a critical track record of repeated RCE and privilege escalation vulnerabilities across Windows, Office, and cloud services. Recent breaches via Entra SSO and critical flaws in Defender and Exchange indicate significant risks for DIB/CMMC environments.

PROFILE
CategoryTechnology VendorWhat they doMicrosoft Corporation develops and supports software, services, devices, and solutions worldwide, including the Microsoft 365 productivity suite, Windows operating system, and Azure cloud platform.OwnershipPublic Websitehttps://www.microsoft.com ↗
SECURITY POSTURE

Microsoft maintains a high volume of critical and high-severity vulnerabilities across its product portfolio, with a pattern of repeated RCE and privilege escalation flaws in core products like Windows, Exchange, and Defender. Recent incidents include a ShinyHunters breach via Microsoft Entra SSO, indicating significant SSO and authentication control weaknesses.

Notable failures
  • ShinyHunters breach via Microsoft Entra SSO (Jan 2026)
  • CVE-2026-33825: Defender local privilege escalation (Apr 2026)
  • CVE-2026-45659: SharePoint RCE via deserialization (Jul 2026)
  • CVE-2026-13781: Chrome sandbox escape (Jun 2026)
  • CVE-2026-57983: Edge Chromium privilege bypass (Jul 2026)
  • CVE-2026-41106: M365 Copilot open redirect (Jul 2026)
Patterns: Repeated RCE in Office/Exchange/SharePoint; Privilege escalation via unpatched Windows components; SSO/Authentication bypasses (Entra); Browser sandbox escape vulnerabilities
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-04-06 CVE-2017-0148 critical Microsoft's SMBv1 server vulnerability (CVE-2017-0148) allowed remote code execution and was actively exploited, often linked to ransomware attacks, demonstrating a critical failure to secure legacy protocols and data transfers.
2022-03-25 CVE-2017-0146 critical A critical Windows vulnerability allowed remote code execution via SMBv1, actively exploited and linked to ransomware attacks, demonstrating a failure to patch a known risk.
2022-02-15 CVE-2018-8174 critical A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution.
2022-02-10 CVE-2017-0144 critical Microsoft's SMBv1 vulnerability (CVE-2017-0144) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.
2022-02-10 CVE-2017-0145 critical Microsoft's SMBv1 vulnerability (CVE-2017-0145) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.
2021-11-03 CVE-2019-0604 critical Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.
2021-11-03 CVE-2017-0199 critical A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks.
2021-11-03 CVE-2021-40444 critical A Microsoft MSHTML vulnerability allowed for remote code execution and was actively exploited, potentially linked to ransomware attacks.
2021-11-03 CVE-2017-0143 critical A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.
2021-11-03 CVE-2017-11882 critical A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks.
2021-11-03 CVE-2021-1675 critical A critical, actively exploited Windows Print Spooler vulnerability allows for remote code execution.
2021-11-03 CVE-2019-0708 critical BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.
2021-11-03 CVE-2020-1472 critical Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments.
2023-01-10 CVE-2023-21674 high Microsoft Windows ALPC flaw exploited in wild for privilege escalation
2022-09-14 CVE-2022-37969 high Microsoft Windows CLFS Driver allows unauthorized escalation of privileges
2026-08-18 CVE-2026-33824 high A double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions allows remote code execution and is actively exploited in the wild.
2026-05-20 CVE-2010-0806 high Microsoft Internet Explorer use-after-free vulnerability enables remote code execution on EoL browsers.
2026-04-22 CVE-2026-33825 critical Microsoft Defender allows local privilege escalation via insufficient access control granularity, enabling ransomware-linked attackers to bypass security controls.
2026-04-14 CVE-2009-0238 high Microsoft Office Excel contains a remote code execution vulnerability that allows attackers to take complete control of a system by opening a specially crafted file.
2026-04-13 CVE-2025-60710 high Microsoft Windows is actively exploited for privilege escalation via CVE-2025-60710, a link-following flaw enabling unauthorized admin access.
2026-03-18 CVE-2026-20963 high Microsoft SharePoint allows remote code execution via deserialization of untrusted data, confirmed as actively exploited.
2025-07-22 CVE-2025-49704 critical Microsoft SharePoint's CVE-2025-49704 code injection flaw allows remote code execution and is actively exploited by ransomware actors.
2025-07-20 CVE-2025-53770 critical Microsoft SharePoint on-premises suffered a deserialization of untrusted data vulnerability allowing remote code execution, actively exploited in the wild and linked to ransomware.
2025-04-08 CVE-2025-29824 critical A use-after-free vulnerability in the Windows CLFS driver allows local privilege escalation and is actively exploited by ransomware.
2025-03-03 CVE-2018-8639 critical A local, authenticated privilege escalation flaw in Windows Win32k allowed attackers to run arbitrary kernel-mode code, leading to ransomware outbreaks.
2024-11-12 CVE-2024-49039 critical An unpatched privilege escalation flaw in Windows Task Scheduler lets attackers bypass AppContainer restrictions and execute privileged RPC calls.
2024-10-22 CVE-2024-38094 critical Microsoft SharePoint's deserialization flaw allowed remote code execution and was actively exploited by ransomware actors.
2024-10-15 CVE-2024-30088 critical A TOCTOU race condition in the Windows kernel allows privilege escalation and is actively exploited in the wild.
2024-06-13 CVE-2024-26169 critical A local privilege escalation flaw in Windows Error Reporting Service lets attackers gain SYSTEM access, and it's actively exploited in the wild.
2024-05-14 CVE-2024-30051 critical A privilege escalation flaw in Microsoft's DWM Core Library lets attackers gain SYSTEM privileges and has been actively exploited in the wild.
2024-04-30 CVE-2024-29988 high Microsoft SmartScreen Prompt bypassed Mark of the Web, enabling remote code execution when chained with two other CVEs.
2024-04-23 CVE-2022-38028 high Microsoft Windows Print Spooler vulnerability (CVE-2022-38028) allows attackers to execute arbitrary code with SYSTEM privileges by modifying a JavaScript constraints file.
2024-03-26 CVE-2023-24955 critical An authenticated attacker with Site Owner privileges could remotely execute code via a code injection vulnerability in Microsoft SharePoint Server.
2024-03-04 CVE-2024-21338 critical A local privilege escalation flaw in Windows appid.sys was actively exploited in the wild to enable ransomware attacks.
2024-02-15 CVE-2024-21410 high Microsoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry.
2024-02-13 CVE-2024-21412 critical An unpatched Windows Internet Shortcut bypass vulnerability was actively exploited in the wild to deliver ransomware.
2024-01-10 CVE-2023-29357 critical An unauthenticated attacker could spoof JWT tokens to escalate to SharePoint admin privileges and execute network attacks.
2023-04-11 CVE-2023-28252 critical An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
2023-04-07 CVE-2019-1388 critical An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns.
2023-03-14 CVE-2023-24880 critical An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file.
2023-02-14 CVE-2023-23376 critical An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
2023-01-10 CVE-2022-41080 critical Microsoft Exchange Server privilege escalation vulnerability (CVE-2022-41080) chainable with RCE CVE-2022-41082 enables full system compromise.
2022-12-13 CVE-2022-44698 critical A bypass vulnerability in Microsoft Defender SmartScreen allowed attackers to evade Mark of the Web protections via a crafted malicious file.
2022-11-08 CVE-2022-41073 critical An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments.
2022-11-08 CVE-2022-41091 critical An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code.
2022-09-30 CVE-2022-41040 critical Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks.
2022-09-30 CVE-2022-41082 critical Microsoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040.
2022-06-14 CVE-2022-30190 critical An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word.
2022-05-25 CVE-2014-4148 high A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild.
2022-05-25 CVE-2015-1671 high A remote code execution flaw in Windows TrueType font handling was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems.
2022-05-25 CVE-2016-0034 critical Microsoft Silverlight's remote code execution vulnerability was actively exploited in the wild and linked to ransomware attacks.
2022-05-25 CVE-2013-0074 critical A double dereference vulnerability in Microsoft Silverlight allowed remote attackers to execute code via crafted HTML objects.
2022-04-06 CVE-2021-31166 high Microsoft's http.sys HTTP protocol stack contained a remote code execution vulnerability that was actively exploited in the wild.
2022-03-25 CVE-2014-6332 high A 2014 OLE automation array RCE in Windows was actively exploited in the wild and remains in CISA's KEV catalog.
2022-03-25 CVE-2014-6324 high Microsoft KDC allows remote authenticated users to escalate to domain admin via privilege escalation.
2022-03-03 CVE-2010-3333 high A stack-based buffer overflow in Microsoft Office's RTF parser allowed remote code execution, and it was actively exploited in the wild.
2022-03-03 CVE-2012-1856 high A 12-year-old unpatched Microsoft Office ActiveX vulnerability in MSCOMCTL.OCX allows remote attackers to execute arbitrary code via crafted documents or web pages.
2022-03-03 CVE-2017-8540 high A memory corruption flaw in Microsoft's Malware Protection Engine allowed remote code execution when scanning specially crafted files.
2022-03-03 CVE-2009-1123 high A 2009 Windows kernel privilege escalation flaw was actively exploited in the wild for years before patching.
2022-03-03 CVE-2009-3129 high A remote code execution vulnerability in Microsoft Excel allows attackers to execute arbitrary code via a malicious spreadsheet file.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
handled well
synthesissevere-fallout-0.70
Widespread acknowledgement of a significant vulnerability, with minimal positive commentary.
synthesissevere-fallout-0.80
Microsoft's vulnerability in the Enhanced Cryptographic Provider was widely flagged by NVD and CISA, indicating critical security failure with no praise for handling.
synthesissevere-fallout-0.80
Critical vulnerability in Microsoft's cryptographic provider enabling privilege escalation, flagged by NIST as a high-severity issue requiring immediate remediation.
synthesissevere-fallout-0.70
Widespread condemnation and association with a major global event.
synthesissevere-fallout-0.70
Significant concern and potential for reputational damage due to a kernel-level privilege escalation vulnerability.
synthesissevere-fallout-0.80
Critical security flaw in core Windows infrastructure
synthesissevere-fallout-0.80
Critical vulnerability in Windows Media Center poses significant remote code execution risk, requiring immediate patching and user awareness.
synthesissevere-fallout-0.80
Critical vulnerability in MSHTML platform poses significant remote code execution risk, requiring immediate patching and user awareness.
synthesissevere-fallout-0.80
Critical security flaw in Windows Installer enabling privilege escalation via symbolic link processing, allowing attackers to bypass file access restrictions.
synthesissevere-fallout-0.60
handled well
synthesissevere-fallout-0.70
Significant negative reception due to unspecified vulnerability and potential privilege escalation.
synthesissevere-fallout-0.70
Widespread acknowledgement of a significant vulnerability, with no positive commentary.
synthesissevere-fallout-0.80
Widespread acknowledgement of a significant vulnerability with potential for exploitation.
synthesissevere-fallout-0.70
Widespread acknowledgement of a significant security issue, coupled with a focus on the sheer volume of vulnerabilities needing remediation, suggests a negative perception of Microsoft's security post
synthesissevere-fallout-0.80
Critical vulnerability in widely used browsers poses significant security risk to enterprise environments.
synthesissevere-fallout-0.70
synthesissevere-fallout-0.80
Critical kernel vulnerability with high risk of information disclosure
synthesissevere-fallout-0.80
Microsoft's kernel vulnerability CVE-2021-33771 was flagged as critical by NVD and CISA, ranking Microsoft 5th in recentbreaches.com breach exposure metrics, indicating significant security fallout.
synthesissevere-fallout-0.80
Microsoft Win3k vulnerability (CVE-2016-0167) is flagged as critical and exploited, indicating severe security posture failure.
synthesissevere-fallout-0.70
synthesissevere-fallout-0.80
Microsoft acknowledged the vulnerability but the inclusion in CISA KEV indicates active exploitation and high risk, reflecting significant security failure.
synthesissevere-fallout-0.60
widely condemned
synthesissevere-fallout-0.60
widely condemned
synthesisnegative-0.50
Vulnerability disclosed but no specific condemnation noted in provided source
synthesissevere-fallout-0.60
handled well
synthesissevere-fallout-0.80
Widespread condemnation due to exploitation and age of vulnerability.
synthesissevere-fallout-0.80
Critical vulnerability in Azure VM Management Extensions allowing remote code execution, requiring immediate patching and user notification.
synthesissevere-fallout-0.80
Microsoft's DWM vulnerability represents a critical security failure with significant implications for enterprise systems.
synthesisnegative-0.60
Acknowledged vulnerability, but no strong condemnation.
FEDRAMP CATALOG PRODUCTS · 4
Open questions: Impact of CVE-2026-13781/13780/13776/13775/13782 on DIB systems · Frequency of patching for CVE-2026-33825 and CVE-2026-41106
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 13:55:47.564311+00:00