HomeSecurityWindows Alert: Zero-day Exploit in Microsoft Defender - Update

Windows Alert: Zero-day Exploit in Microsoft Defender – Update

Microsoft is warning about two zero-day vulnerabilities in Microsoft Defenderthat are reportedly being exploited in real-world attacks. The vulnerabilities are listed as CVE-2026-41091 and CVE-2026-45498 , and involve Escalation Local (LPE) and denial-of-service (DoS) respectively.

Microsoft Defender

Microsoft Defender (and its subsystems) is found on millions of Windows endpoints and servers, both in home and enterprise environments. In practical terms, an LPE bug can turn an initial “click” (e.g. low privileges from phishing, malicious attachment, or stolen credentials) into complete system control, allowing persistence, disabling security tools, and lateral movement.

What we know about CVE-2026-41091

CVE-2026-41091 is described as an “improper link resolution before file access” (also known as link following) issue. Simply put, under certain circumstances, unsafe rendering of links before accessing files could allow an attacker, who already has local access, to escalate their privileges to SYSTEM – the highest level of privilege in Windows.

See also: Pardus Linux: Chain of vulnerabilities allows complete system takeover

Escalating privileges to SYSTEM is a game changer for many attackers, especially in cases where the initial foothold is limited. Just remember that much of the real damage in incident response comes not from the first step, but from escalation and endpoint capture.

What we know about CVE-2026-45498

The second vulnerability, CVE-2026-45498, concerns Denial-of-Service. Although a DoS bug is not as dangerous as an RCE, here the element that raises the risk is that it concerns the protection mechanism: a DoS in Defender can degrade or interrupt critical detection/protection functions, creating a “window” for later stages of the attack.

Windows Alert: Zero-day Exploit in Microsoft Defender - Update

Active exploitation and addition to the KEV List

Both vulnerabilities are reported as “exploited in the wild,” meaning we’re not just talking about a theoretical flaw or PoC. In addition, inclusion on CISA’s Known Exploited Vulnerabilities (KEV) list is considered a strong signal of prioritization: when a vulnerability is on the KEV, organizations tend to put it “higher up” in their patching queues.

According to reports, CISA has set a deadline of June 3, 2026 for the implementation of fixes in federal agencies (FCEB). While this concerns the US, historically such deadlines act as a "regulator" of urgency for the global market as well.

Microsoft Defender: Which products/versions are affected and what are the fixes?

– For CVE-2026-41091: Microsoft Malware Protection Engine (versions 1.1.26030.3008 and earlier reported). Fix: update to 1.1.26040.8.
– For CVE-2026-45498: Microsoft Defender Antimalware Platform (versions 4.18.26030.3011 and earlier reported). Fix: update to 4.18.26040.7.

See also: Drupal Core vulnerability allows RCE attacks on PostgreSQL sites

Note: Microsoft states that in many cases updates are done automatically by default, but in enterprise environments, confirmation (compliance/telemetry) must be made that they have indeed been applied everywhere

What vulnerabilities mean for organizations in Greece

– Many Greek businesses use Windows endpoints with Defender (either standalone or integrated into MDE/EDR strategies). An LPE in SYSTEM dramatically increases the risk in incident response.
– MSPs/IT admins should confirm with reports that engine/platform versions have been updated on all endpoints, especially on servers, VDI pools, “old” laptops and remote endpoints.
– In organizations with strict change management, “automatic” updates may be delayed. An exception/fast-track is needed here.

Windows Alert: Zero-day Exploit in Microsoft Defender - Update

Practical section for admins/users

1) Check that Defender/engine updates are passing normally (policy + telemetry).
2) Confirm versions:
– Malware Protection Engine ≥ 1.1.26040.8
– Defender Antimalware Platform ≥ 4.18.26040.7
3) Watch for suspicious signs of privilege escalation:
– sudden changes in local admin groups
– new scheduled tasks/services
– suspicious processes with SYSTEM
4) If there is a suspicion of compromise, treat it as an incident: log collection, isolation, forensics.

See also: YellowKey BitLocker bypass – Microsoft's mitigations and what IT admins should change

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

IOCs / Timeline

At present, no details have been published on exactly how the exploitation is done, nor are there specific IOCs, so the best defense is to immediately confirm patch level and monitor suspicious activities.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS