Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-33825 | Local Privilege Escalation in Microsoft Defender Antimalware Platform CVE-2026-33825 is an insufficient granularity of access control flaw (CWE-1220) in Microsoft Defender Antimalware Platform that allows an authorized attacker to elevate privileges locally. It is triggered by an attacker who already holds a low-privileged foothold on a machine running Defender, with no user interaction required. Successful exploitation has high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8), granting elevated local rights that facilitate defense evasion, persistence, or ransomware activity. Any organization running Microsoft Defender on Windows endpoints and servers is potentially affected. The flaw is actively exploited in the wild, was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-22 with ransomware use confirmed, and is one of three Microsoft Defender zero-days reported as exploited, two of which were still unpatched at the time of reporting. Do: Apply Microsoft's April 2026 Patch Tuesday updates for the Defender Antimalware Platform (platform/security intelligence updates) per vendor instructions, consistent with CISA BOD 22-01 timelines for KEV entries, and note reports that two of the three exploited Defender zero-days were still unpatched, so monitor for follow-up fixes. Prioritize patching internet-reachable and high-value Windows hosts, and hunt for signs of local privilege escalation and ransomware precursor activity on systems that cannot be updated immediately. | 7.8 | 7% | KEV ransomware |
| masshundreds of millions of Windows endpoints and servers (Defender is the default antimalware on Windows) | |
| CVE-2026-45498 +1 in the same advisory: …41091 | Denial-of-Service Vulnerability in Microsoft Defender Antimalware Platform CVE-2026-45498 is a denial-of-service flaw (CWE-400, uncontrolled resource consumption) in the Microsoft Defender antimalware platform, rated 7.5 (High) with a network attack vector and no privileges or user interaction required. A remote, unauthenticated attacker can trigger excessive resource consumption that disrupts the Defender service, with high impact on availability but no confidentiality or integrity impact per the CVSS scoring. An attacker gains the ability to crash, hang, or disable antimalware protection on targeted systems, potentially leaving endpoints temporarily unprotected. Any deployment of Microsoft Defender — which is the default antimalware on modern Windows and is also deployed as a cloud service — is in scope, and CISA's required action explicitly points defenders to BOD 22-01 guidance for cloud services. The flaw has been added to CISA's KEV catalog (2026-05-20), EPSS assigns it a 63.1% probability of exploitation within 30 days, and headlines confirm it is being exploited in the wild alongside CVE-2026-41091. Do: Apply mitigations per Microsoft's vendor instructions and follow applicable CISA BOD 22-01 guidance for cloud services, as required by the KEV entry. Ensure the Defender antimalware platform and its security intelligence updates are fully current on all endpoints, and check event logs for Defender service crashes or disabled protection that may indicate exploitation. Ransomware use is currently listed as unknown, so treat any Defender outage on exposed systems as a potential precursor to follow-on activity. | 7.5 group max | 63% | KEV |
| masshundreds of millions of Windows endpoints (Defender is the default antimalware on modern Windows client and server) | |
| CVE-2026-45584 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.1 | <1% |
| — | ||
| CVE-2026-45585 | Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable. NVD description · AI analysis pending | 6.8 | 1% | PoC |
| — |
Full article432 words · extracted from helpnetsecurity.com · click to collapse
Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog.
The vulnerabilities
CVE-2026-41091 allows for local privilege elevation (LPE), and is caused by the Microsoft Malware Protection Engine improperly resolving links before accessing files. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft noted.
CVE-2026-45498 can cause a denial-of-service (DoS) state, i.e., it can be used to prevent Microsoft Defender from working as it should.
Both vulnerabilities are publicly disclosed and have been observed being exploited in the wild, Microsoft says.
CVE-2026-41091, along a third Microsoft Defender remote code execution vulnerability (CVE-2026-45584), affect Microsoft Malware Protection Engine v1.26030.3008, and have been fixed in v1.1.26040.8.
CVE-2026-45498 affects Microsoft Defender Antimalware Platform, “a collection of user-mode binaries (…) and kernel-mode drivers that run on top of Windows to keep devices protected against new and prevalent threats”, and has been fixed in v4.18.26040.7.
“For enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically,” Microsoft noted, and said that this Malware Protection Engine update also “includes defense-in-depth updates to help improve security-related features.”
The same goes for the Microsoft Defender Antimalware Platform.
Both the Protection Engine and the Antimalware Platform are used by Microsoft Defender, but also by Microsoft’s System Center Endpoint Protection and Microsoft Security Essentials. (The latter may still run on old, unsupported Windows versions but is no longer updated.)
By adding the two exploited flaws to its KEV catalog, CISA mandated that by June 3, 2026, US federal civilian agencies must either apply Microsoft’s patches or drop the product entirely.
A wave of Microsoft Defender PoC exploits
On April 3 and 15, a disgruntled security researcher who goes by Nightmare Eclipse released proof-of-concept exploits for three Microsoft Defender vulnerabilities: BlueHammer (a LPE flaw), RedSun (another LPE), and UnDefend (a DoS vulnerability).
Huntress incident responders have observed an attacker leveraging the BlueHammer, RedSun, and UnDefend exploits.
BlueHammer, which received the CVE-2026-33825 identifier and has been patched, was added to CISA’s KEV catalog in late April. Researchers Zen Dodd and Yuanpei Xu were credited with reporting it.
Microsoft thanked several researchers for flagging CVE-2026-41091, and none for CVE-2026-45498.
Two days ago, Microsoft shared mitigation advice for CVE-2026-45585 (aka YellowKey), a BitLocker bypass flaw for which Nightmare Eclipse also published a PoC exploit.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/