HomeSecurityMicrosoft Defender vulnerability allows elevation of privilege

Microsoft Defender vulnerability allows elevation of privilege

A newly disclosed vulnerability in Microsoft Defender for Endpointcould allow attackers with local access to escalate their privileges to SYSTEM level, potentially gaining complete control of affected systems.

See also: Windows Defender protection bypassed with XOR techniques

Microsoft Defender vulnerability

The vulnerability, codenamed CVE-2025-26684 , was patched as part of Microsoft's May 2025 Patch Tuesday security updates , which were released yesterday. Security researchers identified the issue as an " external filename or path check " vulnerability in Microsoft Defender for Endpoint, which could be exploited by a privileged attacker to gain local privilege escalation.

The vulnerability received a CVSS score of 6.7 out of 10, classifying it as “Important” rather than “Critical.”

According to the Microsoft Security Response Center, an attacker who successfully exploited this vulnerability could gain SYSTEM privileges, which essentially gives them complete control over the compromised system.

With this level of access, malicious users would be able to install programs, modify or delete data, and create accounts with full administrative privileges. The vulnerability specifically affects Microsoft Defender for Endpoint for Linux, in versions earlier than 101.25XXX.

See also: Latest Microsoft Office for Mac available without subscription

Organizations using this security solution should ensure they apply the latest security update immediately.

Microsoft Defender vulnerability allows elevation of privilege
Microsoft Defender vulnerability allows elevation of privilege

Microsoft has classified the vulnerability as "Unlikely Exploitable," indicating that while the issue is serious, the company believes the likelihood of widespread exploitation is relatively low. Additionally, the company confirmed that there is no evidence that the vulnerability had been publicly disclosed or exploited before the release of the patch.

The vulnerability was discovered through coordinated vulnerability disclosure, with credit to security researchers astraleureka and Rich Mirch from Stratascale. Organizations using Microsoft Defender for Endpoint should prioritize installing the latest security updates as part of their regular update management cycles.

In environments where immediate installation of updates is not possible, security teams should increase monitoring for suspicious privilege escalation attempts and unusual system-level that may indicate exploitation attempts.

See also: Google Workspace implements new policies to improve security

Based on the above, it follows that even if the probability of exploitation of the CVE-2025-26684 vulnerability by malicious users is considered low, its severity should not be underestimated. The possibility of local elevation of privileges at the SYSTEM level is one of the most dangerous forms of violation, as it offers complete control over the operating system.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS