Vulnerabilities > Microsoft > High

DATE CVE VULNERABILITY TITLE RISK
2020-02-11 CVE-2020-0618 Deserialization of Untrusted Data vulnerability in Microsoft SQL Server 2012/2014/2016
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-502
8.8
2020-01-24 CVE-2019-1414 Unspecified vulnerability in Microsoft Visual Studio Code
An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'.
local
low complexity
microsoft
7.8
2020-01-24 CVE-2019-1354 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8
2020-01-24 CVE-2019-1352 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8
2020-01-24 CVE-2019-1351 Use of Incorrectly-Resolved Name or Reference vulnerability in multiple products
A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.
network
low complexity
microsoft opensuse CWE-706
7.5
2020-01-24 CVE-2019-1350 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8
2020-01-24 CVE-2019-1349 Improper Input Validation vulnerability in Microsoft Visual Studio 2017
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
8.8
2020-01-15 CVE-2019-9510 Improper Handling of Exceptional Conditions vulnerability in Microsoft Windows 10 and Windows Server 2019
A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-connected clients to gain access to user sessions without needing to interact with the Windows lock screen.
local
low complexity
microsoft CWE-755
7.8
2020-01-14 CVE-2020-0653 Unspecified vulnerability in Microsoft Office 365 Proplus
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
local
low complexity
microsoft
7.8
2020-01-14 CVE-2020-0652 Out-of-bounds Write vulnerability in Microsoft Excel and Office 365 Proplus
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'.
local
low complexity
microsoft CWE-787
7.8