PT-2026-42157 · Microsoft · Defender
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Defender (affected versions not specified)
Description
An issue exists in the Microsoft Malware Protection Engine within Microsoft Defender involving improper link resolution before file access, also known as link following. This flaw allows an authorized attacker with local access to elevate their privileges to the SYSTEM level. The issue was actively exploited in the wild before a patch was released, making it a significant risk for ransomware and post-compromise attacks. Additionally, a resource exhaustion issue in the Microsoft Defender Antimalware Platform may allow an attacker to cause a denial of service.
Recommendations
Update Microsoft Defender immediately.
Keep Windows fully patched.
Enable multi-factor authentication and follow the principle of least privilege.
Monitor for suspicious privilege escalation activity.
Exploit
Fix
LPE
DoS
Resource Exhaustion
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Defender