Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Damir Moldovanov

#35377of 56,334
7.8Total CVSS
Vulnerabilities · 1
PT-2026-42157
7.8
2026-05-19
Microsoft · Defender · CVE-2026-41091
**Name of the Vulnerable Software and Affected Versions** Microsoft Defender (affected versions not specified) **Description** An issue exists in the Microsoft Malware Protection Engine within Microsoft Defender involving improper link resolution before file access, also known as link following. This flaw allows an authorized attacker with local access to elevate their privileges to the SYSTEM level. The issue was actively exploited in the wild before a patch was released, making it a significant risk for ransomware and post-compromise attacks. Additionally, a resource exhaustion issue in the Microsoft Defender Antimalware Platform may allow an attacker to cause a denial of service. **Recommendations** Update Microsoft Defender immediately. Keep Windows fully patched. Enable multi-factor authentication and follow the principle of least privilege. Monitor for suspicious privilege escalation activity.