Microsoft vulnerabilities

Showing 801 - 850 of 2.7K CVEs

  1. CVE-2021-27056 Published Mar 11, 2021

    Microsoft PowerPoint Remote Code Execution Vulnerability

  2. CVE-2021-27055 Published Mar 11, 2021

    Microsoft Visio Security Feature Bypass Vulnerability

  3. CVE-2021-27054 Published Mar 11, 2021

    Microsoft Excel Remote Code Execution Vulnerability

  4. CVE-2021-27053 Published Mar 11, 2021

    Microsoft Excel Remote Code Execution Vulnerability

  5. CVE-2021-27052 Published Mar 11, 2021

    Microsoft SharePoint Server Information Disclosure Vulnerability

  6. CVE-2021-26411 Published Mar 11, 2021

    Internet Explorer Memory Corruption Vulnerability

  7. CVE-2021-24108 Published Mar 11, 2021

    Microsoft Office Remote Code Execution Vulnerability

  8. CVE-2021-24104 Published Mar 11, 2021

    Microsoft SharePoint Server Spoofing Vulnerability

  9. CVE-2021-27078 Published Mar 3, 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

  10. CVE-2021-27065 Published Mar 3, 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

  11. CVE-2021-26858 Published Mar 3, 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

  12. CVE-2021-26857 Published Mar 3, 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

  13. CVE-2021-26855 Published Mar 3, 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

  14. CVE-2021-26854 Published Mar 3, 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

  15. CVE-2021-26412 Published Mar 3, 2021

    Microsoft Exchange Server Remote Code Execution Vulnerability

  16. CVE-2021-1730 Published Feb 25, 2021

    <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft recommends customers to download inline images from different DNSdomains than the rest of OWA. Please see further instructions in the FAQ to put in place this mitigations.</p>

  17. CVE-2020-17144 Published Dec 10, 2020

    Microsoft Exchange Remote Code Execution Vulnerability

  18. CVE-2020-17143 Published Dec 10, 2020

    Microsoft Exchange Server Information Disclosure Vulnerability

  19. CVE-2020-17142 Published Dec 10, 2020

    Microsoft Exchange Remote Code Execution Vulnerability

  20. CVE-2020-17141 Published Dec 10, 2020

    Microsoft Exchange Remote Code Execution Vulnerability

  21. CVE-2020-17132 Published Dec 10, 2020

    Microsoft Exchange Remote Code Execution Vulnerability

  22. CVE-2020-17129 Published Dec 10, 2020

    Microsoft Excel Remote Code Execution Vulnerability

  23. CVE-2020-17128 Published Dec 10, 2020

    Microsoft Excel Remote Code Execution Vulnerability

  24. CVE-2020-17126 Published Dec 10, 2020

    Microsoft Excel Information Disclosure Vulnerability

  25. CVE-2020-17125 Published Dec 10, 2020

    Microsoft Excel Remote Code Execution Vulnerability

  26. CVE-2020-17124 Published Dec 10, 2020

    Microsoft PowerPoint Remote Code Execution Vulnerability

  27. CVE-2020-17122 Published Dec 10, 2020

    Microsoft Excel Remote Code Execution Vulnerability

  28. CVE-2020-17121 Published Dec 10, 2020

    Microsoft SharePoint Remote Code Execution Vulnerability

  29. CVE-2020-17120 Published Dec 10, 2020

    Microsoft SharePoint Information Disclosure Vulnerability

  30. CVE-2020-17119 Published Dec 10, 2020

    Microsoft Outlook Information Disclosure Vulnerability

  31. CVE-2020-17118 Published Dec 10, 2020

    Microsoft SharePoint Remote Code Execution Vulnerability

  32. CVE-2020-17117 Published Dec 10, 2020

    Microsoft Exchange Remote Code Execution Vulnerability

  33. CVE-2020-17115 Published Dec 10, 2020

    Microsoft SharePoint Server Spoofing Vulnerability

  34. CVE-2020-17089 Published Dec 10, 2020

    Microsoft SharePoint Elevation of Privilege Vulnerability

  35. CVE-2020-17091 Published Nov 11, 2020

    Microsoft Teams Remote Code Execution Vulnerability

  36. CVE-2020-16009 Published Nov 3, 2020

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  37. CVE-2020-16969 Published Oct 16, 2020

    <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the vulnerability, an attacker could include specially crafted OWA messages that could be loaded, without warning or filtering, from the attacker-controlled URL. This callback vector provides an information disclosure tactic used in web beacons and other types of tracking systems.</p> <p>The security update corrects the way that Exchange handles these token validations.</p>

  38. CVE-2020-16957 Published Oct 16, 2020

    <p>A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file.</p> <p>The update addresses the vulnerability by correcting the way the Microsoft Office Access Connectivity Engine handles objects in memory.</p>

  39. CVE-2020-16955 Published Oct 16, 2020

    <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges.</p> <p>To exploit this vulnerability, an attacker would need to convince a user to open a specially crafted file.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Office Click-to-Run (C2R) components handle these files.</p>

  40. CVE-2020-16954 Published Oct 16, 2020

    <p>A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Office handles objects in memory.</p>

  41. CVE-2020-16953 Published Oct 16, 2020

    <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.</p> <p>The security update addresses the vulnerability by correcting how Microsoft SharePoint Server handles objects in memory.</p>

  42. CVE-2020-16952 Published Oct 16, 2020

    <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.</p> <p>Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.</p> <p>The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.</p>

  43. CVE-2020-16951 Published Oct 16, 2020

    <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.</p> <p>Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.</p> <p>The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.</p>

  44. CVE-2020-16950 Published Oct 16, 2020

    <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.</p> <p>The security update addresses the vulnerability by correcting how Microsoft SharePoint Server handles objects in memory.</p>

  45. CVE-2020-16949 Published Oct 16, 2020

    <p>A denial of service vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could cause a remote denial of service against a system.</p> <p>Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Outlook server.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Outlook handles objects in memory.</p>

  46. CVE-2020-16948 Published Oct 16, 2020

    <p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.</p> <p>The security update addresses the vulnerability by correcting how Microsoft SharePoint Server handles objects in memory.</p>

  47. CVE-2020-16947 Published Oct 16, 2020

    <p>A remote code execution vulnerability exists in Microsoft Outlook software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the targeted user. If the targeted user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Outlook software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force users to visit the website. Instead, an attacker would have to convince users to click a link, typically by way of an enticement in an email or instant message, and then convince them to open the specially crafted file.</p> <p>Note that where severity is indicated as Critical in the Affected Products table, the Preview Pane is an attack vector.</p> <p>The security update addresses the vulnerability by correcting how Outlook handles objects in memory.</p>

  48. CVE-2020-16946 Published Oct 16, 2020

    <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.</p> <p>The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user.</p> <p>The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes web requests.</p>

  49. CVE-2020-16945 Published Oct 16, 2020

    <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.</p> <p>The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user.</p> <p>The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes web requests.</p>

  50. CVE-2020-16944 Published Oct 16, 2020

    <p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.</p> <p>An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. These attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the victim, such as change permissions, delete content, steal sensitive information (such as browser cookies) and inject malicious content in the browser of the victim.</p> <p>For this vulnerability to be exploited, a user must click a specially crafted URL that takes the user to a targeted SharePoint Web App site.</p> <p>In an email attack scenario, an attacker could exploit the vulnerability by sending an email message containing the specially crafted URL to the user of the targeted SharePoint Web App site and convincing the user to click the specially crafted URL.</p> <p>In a web-based attack scenario, an attacker would have to host a website that contains a specially crafted URL to the targeted SharePoint Web App site that is used to attempt to exploit these vulnerabilities. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. An attacker would have no way to force users to visit a specially crafted website. Instead, an attacker would have to convince them to visit the website, typically by getting them to click a link in an instant messenger or email message that takes them to the attacker's website, and then convince them to click the specially crafted URL.</p> <p>The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes user web requests.</p>