SEARCH
“Microsoft”
4 products · 1 vendor · 1 entity · 501 events.
FEDRAMP PRODUCTS
open in catalog →
| PRODUCT | PROVIDER | STATUS | IMPACT |
|---|---|---|---|
| Azure Commercial Cloud | Microsoft | Authorized | High |
| Azure Government (includes Dynamics 365) | Microsoft | Authorized | High |
| Microsoft Office 365 GCC High | Microsoft | In Process | High |
| Office 365 Multi-Tenant & Supporting Services | Microsoft | Authorized | Moderate |
VENDORS
FAIL-BOARD ENTITIES
EVENTS
2024-10-08
CISA KEV
Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality.
2024-10-08
CISA KEV
Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.
2024-09-18
CISA KEV
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the...
2024-09-16
CISA KEV
Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction...
2024-09-10
CISA KEV
Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files.
2024-09-10
CISA KEV
Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.
2024-09-10
NVD CVE
Microsoft SQL Server Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Microsoft SQL Server Elevation of Privilege Vulnerability
2024-09-10
NVD CVE
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
2024-08-21
CISA KEV
Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.
2024-08-13
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.
2024-08-13
CISA KEV
Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.
2024-08-13
CISA KEV
Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
2024-08-13
CISA KEV
Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an...
2024-08-13
CISA KEV
Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges.
2024-08-13
CISA KEV
Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file.
2024-08-05
CISA KEV
Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.
2024-07-23
CISA KEV
Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated...
2024-07-09
CISA KEV
Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.
2024-07-09
CISA KEV
Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
2024-06-13
CISA KEV
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
2024-05-14
CISA KEV
Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
2024-05-14
CISA KEV
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.
2024-04-30
CISA KEV
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and...
2024-04-23
CISA KEV
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
2024-03-26
CISA KEV
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
2024-03-04
CISA KEV
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege...
2024-02-29
CISA KEV
Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
2024-02-15
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
2024-02-13
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to...
2024-02-13
CISA KEV
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
2024-01-10
CISA KEV
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This...
2023-11-16
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2023-11-14
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
2023-11-14
CISA KEV
Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.
2023-11-14
CISA KEV
Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
2023-10-10
CISA KEV
Microsoft Skype for Business contains an unspecified vulnerability that allows for privilege escalation.
2023-10-10
CISA KEV
Microsoft WordPad contains an unspecified vulnerability that allows for information disclosure.
2023-10-04
CISA KEV
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges.
2023-09-12
CISA KEV
Microsoft Streaming Service Proxy contains an unspecified vulnerability that allows for privilege escalation.