Skip to content
COOEY
SEARCH
“Microsoft”

4 products · 1 vendor · 1 entity · 501 events.

FEDRAMP PRODUCTS open in catalog →
PRODUCTPROVIDERSTATUSIMPACT
Azure Commercial CloudMicrosoftAuthorizedHigh
Azure Government (includes Dynamics 365)MicrosoftAuthorizedHigh
Microsoft Office 365 GCC HighMicrosoftIn ProcessHigh
Office 365 Multi-Tenant & Supporting ServicesMicrosoftAuthorizedModerate
EVENTS
2022-06-08 CISA KEV
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.
2022-05-25 CISA KEV
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
2022-05-25 CISA KEV
Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.
2022-05-25 CISA KEV
Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an...
2022-05-25 CISA KEV
Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
2022-05-25 CISA KEV
Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
2022-05-25 CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
2022-05-25 CISA KEV
Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
2022-05-25 CISA KEV
Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.
2022-05-25 CISA KEV
Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
2022-05-25 CISA KEV
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
2022-05-25 CISA KEV
The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
2022-05-24 CISA KEV
An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to...
2022-05-24 CISA KEV
Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.
2022-05-24 CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.
2022-05-24 CISA KEV
The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.
2022-05-24 CISA KEV
Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
2022-05-24 CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
2022-05-23 CISA KEV
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
2022-05-04 CISA KEV
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
2022-05-04 CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2022-04-25 CISA KEV
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
2022-04-25 CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2022-04-25 CISA KEV
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
2022-04-25 CISA KEV
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
2022-04-19 CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.
2022-04-13 CISA KEV
Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
2022-04-13 CISA KEV
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11 CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-11 CISA KEV
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
2022-04-06 CISA KEV
Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.
2022-04-06 CISA KEV
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
2022-03-31 CISA KEV
Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
2022-03-28 CISA KEV
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
2022-03-28 CISA KEV
Microsoft Windows Event Tracing contains an unspecified vulnerability which can allow for privilege escalation.
2022-03-28 CISA KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
2022-03-28 CISA KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
2022-03-28 CISA KEV
The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
◀ PREV PAGE 06 / 13 NEXT ▶