ZeroHour

CVE-2026-33825

KEV ransomwaremass1

Local Privilege Escalation in Microsoft Defender Antimalware Platform

CISA: Microsoft Defender Insufficient Granularity of Access Control Vulnerability

CVSS 3.1
7.8 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2026-33825 is an insufficient granularity of access control flaw (CWE-1220) in Microsoft Defender Antimalware Platform that allows an authorized attacker to elevate privileges locally. It is triggered by an attacker who already holds a low-privileged foothold on a machine running Defender, with no user interaction required. Successful exploitation has high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8), granting elevated local rights that facilitate defense evasion, persistence, or ransomware activity. Any organization running Microsoft Defender on Windows endpoints and servers is potentially affected. The flaw is actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-22 with ransomware use confirmed, and is one of three Microsoft Defender zero-days reported as exploited, two of which were still unpatched at the time of reporting.

What to do: Apply Microsoft's April 2026 Patch Tuesday updates for the Defender Antimalware Platform (platform/security intelligence updates) per vendor instructions, consistent with CISA BOD 22-01 timelines for KEV entries, and note reports that two of the three exploited Defender zero-days were still unpatched, so monitor for follow-up fixes. Prioritize patching internet-reachable and high-value Windows hosts, and hunt for signs of local privilege escalation and ransomware precursor activity on systems that cannot be updated immediately.

Affected
Microsoft Defender Antimalware Platform
Estimated exposure
masshundreds of millions of Windows endpoints and servers (Defender is the default antimalware on Windows) — Microsoft Defender Antimalware Platform ships by default on Windows 10/11 and Windows Server, so effectively the entire Windows installed base is plausibly affected; this is a deployment-based order-of-magnitude estimate, as no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Defender
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
defender antimalware platform
Weakness
CWE-1220
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news