SEARCH
“Microsoft”
4 products · 1 vendor · 1 entity · 501 events.
FEDRAMP PRODUCTS
open in catalog →
| PRODUCT | PROVIDER | STATUS | IMPACT |
|---|---|---|---|
| Azure Commercial Cloud | Microsoft | Authorized | High |
| Azure Government (includes Dynamics 365) | Microsoft | Authorized | High |
| Microsoft Office 365 GCC High | Microsoft | In Process | High |
| Office 365 Multi-Tenant & Supporting Services | Microsoft | Authorized | Moderate |
VENDORS
FAIL-BOARD ENTITIES
EVENTS
2023-09-12
CISA KEV
Microsoft Word contains an unspecified vulnerability that allows for information disclosure.
2023-08-09
CISA KEV
Microsoft .NET Core and Visual Studio contain an unspecified vulnerability that allows for denial-of-service (DoS).
2023-07-17
CISA KEV
Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.
2023-07-11
CISA KEV
Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.
2023-07-11
CISA KEV
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for privilege escalation.
2023-07-11
CISA KEV
Microsoft Windows Defender SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the Open File - Security Warning prompt.
2023-06-22
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2023-05-09
CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation up to SYSTEM privileges.
2023-04-11
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2023-04-07
CISA KEV
Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
2023-03-30
CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website.
2023-03-14
CISA KEV
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
2023-03-14
CISA KEV
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.
2023-02-14
NVD CVE
Microsoft Word Remote Code Execution Vulnerability
2023-02-14
CISA KEV
Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated attack on a targeted system.
2023-02-14
CISA KEV
Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.
2023-02-14
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2023-01-10
CISA KEV
Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.
2023-01-10
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
2022-12-13
CISA KEV
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
2022-11-14
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2022-11-08
CISA KEV
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.
2022-11-08
CISA KEV
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
2022-11-08
CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
2022-11-08
CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
2022-10-11
CISA KEV
Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.
2022-09-30
CISA KEV
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
2022-09-30
CISA KEV
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the...
2022-09-15
CISA KEV
Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this...
2022-09-14
CISA KEV
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
2022-08-18
CISA KEV
Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
2022-08-09
CISA KEV
A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.
2022-07-12
CISA KEV
Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.
2022-07-01
CISA KEV
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
2022-06-08
CISA KEV
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.
2022-06-08
CISA KEV
Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.
2022-06-08
CISA KEV
Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution.
2022-06-08
CISA KEV
The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to...
2022-06-08
CISA KEV
Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.
2022-06-08
CISA KEV
Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.