Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-11-12 CVE-2019-0721 Improper Input Validation vulnerability in Microsoft products
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
critical
9.1
2019-11-12 CVE-2019-0719 Improper Input Validation vulnerability in Microsoft products
A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
critical
9.1
2019-10-10 CVE-2019-1372 Unspecified vulnerability in Microsoft Azure APP Service on Azure Stack
An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system thereby escaping the Sandbox.The security update addresses the vulnerability by ensuring that Azure App Service sanitizes user inputs., aka 'Azure App Service Remote Code Execution Vulnerability'.
network
low complexity
microsoft
critical
10.0
2019-10-10 CVE-2019-1365 Unspecified vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the context of NT AUTHORITY\system escaping the Sandbox.The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests., aka 'Microsoft IIS Server Elevation of Privilege Vulnerability'.
network
low complexity
microsoft
critical
9.9
2019-09-11 CVE-2019-1306 Improper Input Validation vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
critical
9.8
2019-07-15 CVE-2019-1109 Improper Input Validation vulnerability in Microsoft Office and Office 365
A spoofing vulnerability exists when Microsoft Office Javascript does not check the validity of the web page making a request to Office documents.An attacker who successfully exploited this vulnerability could read or write information in Office documents.The security update addresses the vulnerability by correcting the way that Microsoft Office Javascript verifies trusted web pages., aka 'Microsoft Office Spoofing Vulnerability'.
network
low complexity
microsoft CWE-20
critical
9.1
2019-07-15 CVE-2019-1072 Improper Input Validation vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
critical
9.8
2019-07-15 CVE-2019-0785 Out-of-bounds Write vulnerability in Microsoft products
A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-787
critical
9.8
2019-05-16 CVE-2019-0938 Unspecified vulnerability in Microsoft Edge
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
network
high complexity
microsoft
critical
9.0
2019-05-16 CVE-2019-0725 Out-of-bounds Write vulnerability in Microsoft products
A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-787
critical
9.8