Microsoft says two Defender flaws are under active exploitation

by

Microsoft said two vulnerabilities in Defender, one that could let a local attacker gain SYSTEM privileges and another that could trigger a denial of service, are being exploited in the wild. The flaws are tracked as CVE-2026-41091 and CVE-2026-45498.

KEY FACTS

  • Privilege escalation CVE-2026-41091 has a CVSS score of 7.8 and could raise privileges locally.
  • Denial of service CVE-2026-45498 has a CVSS score of 4.0 and affects Defender.
  • Fixes The issues were addressed in Microsoft Defender Antimalware Platform versions 1.1.26040.8 and 4.18.26040.7.
  • Government action CISA added both flaws to its Known Exploited Vulnerabilities catalog.

In a Microsoft security advisory, the company said improper link resolution before file access in Defender can let an authorized attacker elevate privileges locally. The disclosure said the impact could include SYSTEM-level access.

The second issue affects Defender through a denial-of-service condition. Microsoft said systems with Defender disabled are not affected, and no manual action is required to install the update because the platform and definition files update automatically.

Microsoft credited five researchers and researchers known as Sibusiso, Diffract, Andrew C. Dorman, Damir Moldovanov and an unnamed researcher for reporting the flaw. The company did not give details on how the vulnerabilities are being used in attacks.

CISA said federal civilian executive branch agencies must apply the fixes by June 3, 2026. The catalogue update came as Microsoft also disclosed recent exploitation of an Exchange Server cross-site scripting flaw and added several older Microsoft and Adobe vulnerabilities to the list.

WHY IT MATTERS

The disclosure adds to a run of recently exploited Microsoft flaws and shows that even security software can become a target. For users and administrators, the update affects systems that rely on Defender for protection and highlights the need to confirm current platform and definition versions.