Skip to content
COOEY
SEARCH
“Microsoft”

4 products · 1 vendor · 1 entity · 501 events.

FEDRAMP PRODUCTS open in catalog →
PRODUCTPROVIDERSTATUSIMPACT
Azure Commercial CloudMicrosoftAuthorizedHigh
Azure Government (includes Dynamics 365)MicrosoftAuthorizedHigh
Microsoft Office 365 GCC HighMicrosoftIn ProcessHigh
Office 365 Multi-Tenant & Supporting ServicesMicrosoftAuthorizedModerate
EVENTS
2022-03-28 CISA KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fonts.
2022-03-28 CISA KEV
JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
2022-03-28 CISA KEV
Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
2022-03-28 CISA KEV
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges.
2022-03-28 CISA KEV
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
2022-03-28 CISA KEV
Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.
2022-03-28 CISA KEV
afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.
2022-03-28 CISA KEV
Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.
2022-03-25 CISA KEV
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
2022-03-25 CISA KEV
Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
2022-03-25 CISA KEV
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
2022-03-25 CISA KEV
The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
2022-03-15 CISA KEV
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
2022-03-03 CISA KEV
Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.
2022-03-03 CISA KEV
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary...
2022-03-03 CISA KEV
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
2022-03-03 CISA KEV
A remote code execution vulnerability exists in Microsoft Excel when the software fails to properly handle objects in memory.
2022-03-03 CISA KEV
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption.
2022-03-03 CISA KEV
A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.
2022-03-03 CISA KEV
A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.
2022-03-03 CISA KEV
The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.
2022-03-03 CISA KEV
Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.
2022-03-03 CISA KEV
The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.
2022-03-03 CISA KEV
smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.
2022-03-03 CISA KEV
Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
2022-03-03 CISA KEV
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability...
2022-03-03 CISA KEV
Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.
2022-03-03 CISA KEV
A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands.
2022-03-03 CISA KEV
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607...
2022-03-03 CISA KEV
Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
2022-03-03 CISA KEV
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
2022-03-03 CISA KEV
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.
2022-03-03 CISA KEV
Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
2022-03-03 CISA KEV
Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.
2022-03-03 CISA KEV
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
2022-02-25 CISA KEV
A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory.
2022-02-25 CISA KEV
Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
◀ PREV PAGE 07 / 13 NEXT ▶