Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Microsoft — Vulnerabilities & Security Advisories 10805

Browse all 10805 CVE security advisories affecting Microsoft. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Microsoft operates as a global technology corporation primarily providing enterprise software, cloud computing services, and consumer electronics. Its extensive software portfolio, including Windows operating systems and Office suites, has historically been associated with a high volume of Common Vulnerabilities and Exposures (CVEs), currently totaling 8,272. Common vulnerability classes affecting these products include remote code execution, cross-site scripting, and privilege escalation, often stemming from complex legacy codebases and extensive feature sets. Notable security incidents include the 2021 SolarWinds supply chain compromise, which impacted Microsoft’s Orion platform, and various critical zero-day exploits in Internet Explorer and Edge browsers. The company maintains a dedicated security response team and regularly issues patches through Windows Update to mitigate these risks, though the sheer scale of its ecosystem continues to present significant attack surfaces for threat actors seeking unauthorized access or data exfiltration.

CVE ID Title CVSS Severity Published
CVE-2023-21529 Microsoft Exchange Server Remote Code Execution Vulnerability — Microsoft Exchange Server 2013 Cumulative Update 23 CWE-502 8.8 High 2023-02-14
CVE-2023-23382 Azure Machine Learning Compute Instance Information Disclosure Vulnerability — Azure Machine Learning CWE-257 6.5 Medium 2023-02-14
CVE-2023-23379 Microsoft Defender for IoT Elevation of Privilege Vulnerability — Microsoft Defender for IoT CWE-23 7.8 High 2023-02-14
CVE-2023-23378 Print 3D Remote Code Execution Vulnerability — Print 3D CWE-122 7.8 High 2023-02-14
CVE-2023-23374 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — Microsoft Edge for Android 8.3 High 2023-02-14
CVE-2023-21573 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.0 5.4 Medium 2023-02-14
CVE-2023-21572 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.0 6.5 Medium 2023-02-14
CVE-2023-21571 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.0 CWE-79 5.4 Medium 2023-02-14
CVE-2023-21568 Microsoft SQL Server Integration Service (VS extension) Remote Code Execution Vulnerability — SQL Server Integration Services for Visual Studio 2019 CWE-502 7.3 High 2023-02-14
CVE-2023-21570 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.0 CWE-79 5.4 Medium 2023-02-14
CVE-2023-21721 Microsoft OneNote Elevation of Privilege Vulnerability — Microsoft OneNote for Android CWE-287 6.5 Medium 2023-02-14
CVE-2023-21720 Microsoft Edge (Chromium-based) Tampering Vulnerability — Microsoft Edge (Chromium-based) CWE-126 5.3 Medium 2023-02-14
CVE-2023-21718 Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability — Microsoft SQL Server 2008 R2 Service Pack 3 (QFE) CWE-191 7.8 High 2023-02-14
CVE-2023-21707 Microsoft Exchange Server Remote Code Execution Vulnerability — Microsoft Exchange Server 2013 Cumulative Update 23 CWE-502 8.8 High 2023-02-14
CVE-2023-21706 Microsoft Exchange Server Remote Code Execution Vulnerability — Microsoft Exchange Server 2013 Cumulative Update 23 CWE-502 8.8 High 2023-02-14
CVE-2023-21705 Microsoft SQL Server Remote Code Execution Vulnerability — Microsoft SQL Server 2012 for x64-based Systems Service Pack 4 (QFE) CWE-321 8.8 High 2023-02-14
CVE-2023-21704 Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability — Microsoft SQL Server 2014 Service Pack 3 (CU 4) CWE-190 7.8 High 2023-02-14
CVE-2023-21807 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability — Microsoft Dynamics 365 (on-premises) version 9.0 CWE-79 6.5 Medium 2023-02-14
CVE-2023-21806 Power BI Report Server Spoofing Vulnerability — Power BI Report Server - January 2023 CWE-79 8.2 High 2023-02-14
CVE-2023-21794 Microsoft Edge (Chromium-based) Spoofing Vulnerability — Microsoft Edge (Chromium-based) 4.3 Medium 2023-02-14
CVE-2023-21777 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability — Azure App Service on Azure Stack Hub CWE-284 8.7 High 2023-02-14
CVE-2023-21684 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability — Windows 10 Version 1507 CWE-191 8.8 High 2023-02-14
CVE-2023-21528 Microsoft SQL Server Remote Code Execution Vulnerability — Microsoft SQL Server 2008 R2 Service Pack 3 (QFE) CWE-122 7.8 High 2023-02-14
CVE-2023-21719 Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability — Microsoft Edge (Chromium-based) 6.5 Medium 2023-01-23
CVE-2023-21796 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability — Microsoft Edge (Chromium-based) Extended Stable 8.3 High 2023-01-23
CVE-2023-21795 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability — Microsoft Edge (Chromium-based) CWE-416 8.3 High 2023-01-23
CVE-2023-21775 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — Microsoft Edge (Chromium-based) 8.3 High 2023-01-23
CVE-2023-21793 3D Builder Remote Code Execution Vulnerability — 3D Builder CWE-122 7.8 High 2023-01-10
CVE-2023-21792 3D Builder Remote Code Execution Vulnerability — 3D Builder CWE-122 7.8 High 2023-01-10
CVE-2023-21791 3D Builder Remote Code Execution Vulnerability — 3D Builder CWE-122 7.8 High 2023-01-10

This page lists every published CVE security advisory associated with Microsoft. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.