SEARCH
“Microsoft”
4 products · 1 vendor · 1 entity · 501 events.
FEDRAMP PRODUCTS
open in catalog →
| PRODUCT | PROVIDER | STATUS | IMPACT |
|---|---|---|---|
| Azure Commercial Cloud | Microsoft | Authorized | High |
| Azure Government (includes Dynamics 365) | Microsoft | Authorized | High |
| Microsoft Office 365 GCC High | Microsoft | In Process | High |
| Office 365 Multi-Tenant & Supporting Services | Microsoft | Authorized | Moderate |
VENDORS
FAIL-BOARD ENTITIES
EVENTS
2022-05-23
CISA KEV
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk.
2022-05-23
CISA KEV
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system.
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
2022-05-23
CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
2022-05-23
CISA KEV
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from...
2022-05-23
CISA KEV
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.
2022-04-15
CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-03-28
CISA KEV
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
2022-03-28
CISA KEV
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
2022-03-28
CISA KEV
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
2022-03-28
CISA KEV
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-03-25
CISA KEV
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
2022-03-25
CISA KEV
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of...
2022-03-25
CISA KEV
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
2022-03-15
CISA KEV
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an...
2022-03-15
CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
2022-03-03
CISA KEV
A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.
2022-03-03
CISA KEV
A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.
2022-03-03
CISA KEV
A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially crafted OLE object.
2022-03-03
CISA KEV
This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer.
2022-02-25
CISA KEV
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
2022-02-15
CISA KEV
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
2022-02-15
CISA KEV
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
2022-02-15
CISA KEV
Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...
2022-02-10
CISA KEV
If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.
2022-01-10
CISA KEV
A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.
2022-01-10
CISA KEV
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
2021-12-15
CISA KEV
Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers...