ZeroHour

CVE-2026-41091

KEV PoC mass

Link-Following Local Privilege Escalation in Microsoft Defender (Actively Exploited)

CISA: Microsoft Defender Link Following Vulnerability

CVSS 3.1
7.8 high
EPSS
8%p95
Published
()
KEV added
AI analysis

Microsoft Defender, through its Microsoft Malware Protection Engine component, contains an improper link-resolution ('link following', CWE-59) flaw in which the engine fails to properly resolve a link, such as a shortcut or symbolic link, before accessing the file it points to. An authorized attacker who already holds limited local privileges can plant or manipulate such a link so that Defender, operating in its privileged context, follows it and performs file operations on the attacker's behalf, elevating the attacker to SYSTEM privileges on the local machine with no user interaction (CVSS 7.8: AV:L/PR:L/UI:N with high C/I/A). Any Windows system running Microsoft Defender is in scope, with version ranges not specified in the available data; because Defender is the built-in default antivirus on Windows 10/11 and is widely deployed on Windows Server, exposure effectively spans the entire Windows installed base. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2026-05-20, and press reports describe a 'RoguePlanet' Defender zero-day granting SYSTEM access even on fully patched Windows, amid Microsoft's record-setting 206-CVE Patch Tuesday that coverage flagged as including one bug under active attack. A public proof-of-concept is available on GitHub, EPSS assigns an 8.2% probability of exploitation within 30 days (95th percentile), and ransomware use is not yet confirmed.

What to do: Apply Microsoft's current security updates — including the record June 2026 Patch Tuesday release (206 vulnerabilities) — across all Windows clients and servers, and verify the Microsoft Defender / Malware Protection Engine update actually installed rather than definitions only. Because the flaw gives a low-privileged local user SYSTEM access and is actively exploited with a public PoC available, prioritize endpoints where untrusted or low-privileged users log on locally (workstations, VDI, multi-user servers), and organizations subject to CISA BOD 22-01 must apply the required mitigations per vendor instructions or discontinue use per the KEV requirement. On hosts not yet patched, hunt for signs of local privilege escalation involving Defender, and note that ransomware use has not yet…

Affected
Microsoft Defender
Microsoft Malware Protection Engine
Estimated exposure
mass≈1 billion+ Windows devices (Defender is the default, enabled-by-default antivirus on Windows 10/11) — No install counts were provided, but Microsoft Defender Antivirus is the default, enabled-by-default AV on Windows 10/11 and is broadly deployed on Windows Server, so plausible exposure spans the Windows installed base on the order of a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Defender
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
malware protection engine
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news