Skip to main content

Microsoft security briefs

3328 published alerts for Microsoft products and services.

Actively exploited (KEV)Ransomware

CVE-2025-49706

Microsoft SharePoint Improper Authentication Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-49706). Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706. CISA remediation due date: 2025-07-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-49704

Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-49704). Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. CISA remediation due date: 2025-07-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-53770

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-53770). Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. CISA remediation due date: 2025-07-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-29824

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-29824). Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2025-04-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-26633

Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-26633). Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. CISA remediation due date: 2025-04-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2018-8639

Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-8639). Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. CISA remediation due date: 2025-03-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-49039

Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-49039). Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. CISA remediation due date: 2024-12-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-38094

Microsoft SharePoint Deserialization Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-38094). Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. CISA remediation due date: 2024-11-12. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-30088

Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30088). Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. CISA remediation due date: 2024-11-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-0618

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Microsoft SQL Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0618). Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. CISA remediation due date: 2024-10-09. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-26169

Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-26169). Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. CISA remediation due date: 2024-07-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-30051

Microsoft DWM Core Library Privilege Escalation Vulnerability

Microsoft DWM Core Library is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-30051). Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges. CISA remediation due date: 2024-06-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-24955

Microsoft SharePoint Server Code Injection Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-24955). Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. CISA remediation due date: 2024-04-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-21338

Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21338). Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. CISA remediation due date: 2024-03-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-21412

Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-21412). Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. CISA remediation due date: 2024-03-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-29357

Microsoft SharePoint Server Privilege Escalation Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-29357). Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. CISA remediation due date: 2024-01-31. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-36884

Microsoft Windows Search Remote Code Execution Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-36884). Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. CISA remediation due date: 2023-08-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-28252

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-28252). Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2023-05-02. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2019-1388

Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1388). Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context. CISA remediation due date: 2023-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-24880

Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-24880). Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. CISA remediation due date: 2023-04-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-23376

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-23376). Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. CISA remediation due date: 2023-03-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-41080

Microsoft Exchange Server Privilege Escalation Vulnerability

Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-41080). Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. CISA remediation due date: 2023-01-31. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-44698

Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

Microsoft Defender is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-44698). Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file. CISA remediation due date: 2023-01-03. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2022-41091

Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-41091). Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. CISA remediation due date: 2022-12-09. If you need help checking exposure, call (864) 335-9223.