PT-2026-42157 · Microsoft · Defender

·

CVE-2026-41091

·

Published

2026-05-19

·

Updated

2026-08-14

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Defender (affected versions not specified)
Description An issue exists in the Microsoft Malware Protection Engine within Microsoft Defender involving improper link resolution before file access, also known as link following. This flaw allows an authorized attacker with local access to elevate their privileges to the SYSTEM level. The issue was actively exploited in the wild before a patch was released, making it a significant risk for ransomware and post-compromise attacks. Additionally, a resource exhaustion issue in the Microsoft Defender Antimalware Platform may allow an attacker to cause a denial of service.
Recommendations Update Microsoft Defender immediately. Keep Windows fully patched. Enable multi-factor authentication and follow the principle of least privilege. Monitor for suspicious privilege escalation activity.

Exploit

Fix

LPE

DoS

Resource Exhaustion

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07109
BDU:2026-07110
CVE-2026-41091

Affected Products

Defender