SEARCH
“Microsoft”
4 products · 1 vendor · 1 entity · 501 events.
FEDRAMP PRODUCTS
open in catalog →
| PRODUCT | PROVIDER | STATUS | IMPACT |
|---|---|---|---|
| Azure Commercial Cloud | Microsoft | Authorized | High |
| Azure Government (includes Dynamics 365) | Microsoft | Authorized | High |
| Microsoft Office 365 GCC High | Microsoft | In Process | High |
| Office 365 Multi-Tenant & Supporting Services | Microsoft | Authorized | Moderate |
VENDORS
FAIL-BOARD ENTITIES
EVENTS
2026-07-14
NVD CVE
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
2026-07-03
NVD CVE
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
2026-07-01
CISA KEV
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
2026-05-22
NVD CVE
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
2026-05-20
CISA KEV
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The...
2026-05-20
CISA KEV
Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
2026-05-20
CISA KEV
Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be...
2026-05-20
CISA KEV
Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
2026-05-20
CISA KEV
Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
2026-05-20
CISA KEV
Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
2026-05-15
CISA KEV
Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the...
2026-04-28
CISA KEV
Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
2026-04-22
CISA KEV
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
2026-04-14
CISA KEV
Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a...
2026-04-14
CISA KEV
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
2026-04-13
CISA KEV
Microsoft Windows contains a link following vulnerability that allows for privilege escalation
2026-04-13
CISA KEV
Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution.
2026-04-13
CISA KEV
Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation
2026-04-13
CISA KEV
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
2026-04-03
NVD CVE
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
2026-04-03
NVD CVE
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
2026-03-18
CISA KEV
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
2026-02-17
CISA KEV
Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the...
2026-02-12
CISA KEV
Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are...
2026-02-10
CISA KEV
Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.
2026-02-10
CISA KEV
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.
2026-02-10
CISA KEV
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
2026-02-10
CISA KEV
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.
2026-02-10
CISA KEV
Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.
2026-02-10
CISA KEV
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
2026-01-13
CISA KEV
Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
2026-01-07
CISA KEV
Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that...
2025-12-09
CISA KEV
Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
2025-11-12
CISA KEV
Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker...
2025-10-24
CISA KEV
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
2025-10-20
CISA KEV
Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to...
2025-10-14
CISA KEV
Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.