Microsoft security briefs
3328 published alerts for Microsoft products and services.
Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
Microsoft Edge and Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0878). Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
Microsoft Exchange Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-0688). Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Microsoft Internet Explorer is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1367). Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-1215). Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0859). Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0803). Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
Microsoft Remote Desktop Services is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0708). Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2019-0604). Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Memory Corruption Vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-0802). Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office Memory Corruption Vulnerability
Microsoft Office is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-11882). Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Office and WordPad Remote Code Execution Vulnerability
Microsoft Office and WordPad is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0199). Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-0143). Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-7255). Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2016-0167). Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
Microsoft Windows is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2014-1812). Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.
Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability
Microsoft MSCOMCTL.OCX is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2012-0158). Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user. CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.