Summary
An authorized local attacker can abuse improper link resolution in Microsoft Defender's Malware Protection Engine. During privileged file access or scanning, Defender may follow an attacker-controlled symbolic link or junction instead of the intended path, redirecting a high-privilege operation onto a protected target. Successful exploitation can elevate a low-privilege Windows account to SYSTEM, and the CVE is being actively exploited in the wild.
Why Fix Soon?
5/6Exploitation Details
Gain SYSTEM-level privileges on the local Windows host.
Privilege EscalationAffected Software
| Product | Affected Versions |
|---|---|
| Microsoft Malware Protection Engine | before 1.1.26040.8 |
Microsoft's antimalware engine that scans files, detects threats, and supports malware-removal logic for Microsoft Defender and related endpoint protection products.
Affected ComponentFile-access and link-resolution handling in the Microsoft Malware Protection Engine scanning path.
File-access and link-resolution handling in the Microsoft Malware Protection Engine scanning path.
Not available
Not available
Update Microsoft Malware Protection Engine to version 1.1.26040.8 or later; Defender engine updates are delivered through Microsoft's normal update channels, but managed environments should verify the new engine version is deployed.
Update Microsoft Malware Protection Engine to version 1.1.26040.8 or later; Defender engine updates are delivered through Microsoft's normal update channels, but managed environments should verify the new engine version is deployed.
Probability of exploitation in the next 30 days
Worse than 94% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (1)
- •cpe:2.3:a:microsoft:malware_protection_engine:*:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| www.cisa.gov | Known Exploited Vulnerabilities Catalog |
| msrc.microsoft.com | CVE-2026-41091 Security Update Guide |
| support.microsoft.com | Microsoft Malware Protection Engine deployment information |
| www.cyber.gc.ca | Microsoft security advisory AV26-489 |
| www.tenable.com | CVE-2026-41091 |
| www.bleepingcomputer.com | Microsoft warns of new Defender zero-days exploited in attacks |
| www.csoonline.com | Microsoft patches two zero-day flaws in Defender |
Priority History
Initial analysis