Microsoft

Security Scorecard

Score

25F

Total CVEs

641

Patch Rate

28%

178 patched

Avg Response

1052d

days to patch

Critical Gaps

35

exploitable, no detection

Severity Breakdown

Critical17
High299
Medium264
Low40

Patch Status

Patched178 (28%)
Partial/Workaround31 (5%)
Unpatched432 (67%)

CVEs (645)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-27489Azure Local Privilege EscalationHigh7.8-Patched
CVE-2025-26627Azure Arc Command InjectionHigh7.0-Workaround
CVE-2025-21298-Critical9.8334dUnpatched
CVE-2024-49112-Critical9.8367dUnpatched
CVE-2022-41128Windows Scripting Languages Remote Code Execution VulnerabilityHigh8.8-1dPatched
CVE-2022-41033Windows COM+ Event System Service Elevation of Privilege VulnerabilityHigh7.8-Patched
CVE-2022-37969Windows Common Log File System Driver Elevation of Privilege VulnerabilityHigh7.81dPatched
CVE-2021-34527-High8.8124dPatched
CVE-2021-31956Windows NTFS Elevation of Privilege VulnerabilityHigh7.8-Patched
CVE-2021-26855-Critical9.1245dPatched