ZeroHour

CVE-2026-45498

KEVmass

Denial-of-Service Vulnerability in Microsoft Defender Antimalware Platform

CISA: Microsoft Defender Denial of Service Vulnerability

CVSS 3.1
7.5 high
EPSS
63%p99
Published
()
KEV added
AI analysis

CVE-2026-45498 is a denial-of-service flaw (CWE-400, uncontrolled resource consumption) in the Microsoft Defender antimalware platform, rated 7.5 (High) with a network attack vector and no privileges or user interaction required. A remote, unauthenticated attacker can trigger excessive resource consumption that disrupts the Defender service, with high impact on availability but no confidentiality or integrity impact per the CVSS scoring. An attacker gains the ability to crash, hang, or disable antimalware protection on targeted systems, potentially leaving endpoints temporarily unprotected. Any deployment of Microsoft Defender — which is the default antimalware on modern Windows and is also deployed as a cloud service — is in scope, and CISA's required action explicitly points defenders to BOD 22-01 guidance for cloud services. The flaw has been added to CISA's KEV catalog (2026-05-20), EPSS assigns it a 63.1% probability of exploitation within 30 days, and headlines confirm it is being exploited in the wild alongside CVE-2026-41091.

What to do: Apply mitigations per Microsoft's vendor instructions and follow applicable CISA BOD 22-01 guidance for cloud services, as required by the KEV entry. Ensure the Defender antimalware platform and its security intelligence updates are fully current on all endpoints, and check event logs for Defender service crashes or disabled protection that may indicate exploitation. Ransomware use is currently listed as unknown, so treat any Defender outage on exposed systems as a potential precursor to follow-on activity.

Affected
Microsoft Defender (antimalware platform)
Estimated exposure
masshundreds of millions of Windows endpoints (Defender is the default antimalware on modern Windows client and server) — Microsoft Defender ships enabled by default on Windows 10/11 and Windows Server, so the plausible installed base is on the order of hundreds of millions of devices, though the subset reachable by this network-triggerable flaw is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft Defender Denial of Service Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Defender
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
defender antimalware platform
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news