CVE-2026-45498Active Exploitation(microsoft / defender_antimalware_platform)

CRITICALCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 38 mentions and remains active

Immediate actions

  • Patch microsoft defender_antimalware_platform systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft Defender Denial of Service Vulnerability

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-400

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • defender_antimalware_platform

Threat summary

  • Active exploitation appears in 72 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 104 mentions across 31 observed days

What's happening

  • Active exploitation reported across 72 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 56 signals
  • Technical details provided in 59 signals
  • General: 12 classified signals
  • Peaked 29d ago at 38 mentions (2026-05-21); latest day: 1
  • 104 total mentions across 31 days

Affected systems

Vendors
Products
defender_antimalware_platform

Deep dive

Activity timeline104 mentions / 31d
010192938Mentions · 2026-05-20: 6Mentions · 2026-05-21: 38Mentions · 2026-05-22: 11Mentions · 2026-05-24: 5Mentions · 2026-05-25: 2Mentions · 2026-05-26: 1Mentions · 2026-05-27: 1Mentions · 2026-05-28: 2Mentions · 2026-05-29: 1Mentions · 2026-05-31: 1Mentions · 2026-06-01: 3Mentions · 2026-06-02: 4Mentions · 2026-06-03: 2Mentions · 2026-06-05: 2Mentions · 2026-06-06: 1Mentions · 2026-06-07: 6Mentions · 2026-06-08: 1Mentions · 2026-06-10: 4Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-14: 1Mentions · 2026-06-16: 1Mentions · 2026-06-17: 1Mentions · 2026-06-24: 1Mentions · 2026-06-29: 1Mentions · 2026-06-30: 1Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Mentions · 2026-07-12: 1Mentions · 2026-09-02: 1Mentions · 2026-09-28: 1PoC Mentioned / Linked · 2026-05-21: 3PoC Mentioned / Linked · 2026-06-17: 1PoC Mentioned / Linked · 2026-06-29: 1PoC Mentioned / Linked · 2026-07-06: 1Exploit Tool / Code · 2026-05-21: 1Exploit Tool / Code · 2026-06-05: 1Exploit Tool / Code · 2026-06-17: 1Exploit Tool / Code · 2026-06-29: 1Active Exploitation · 2026-05-20: 4Active Exploitation · 2026-05-21: 33Active Exploitation · 2026-05-22: 9Active Exploitation · 2026-05-25: 2Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-05-29: 1Active Exploitation · 2026-06-02: 3Active Exploitation · 2026-06-03: 2Active Exploitation · 2026-06-05: 2Active Exploitation · 2026-06-06: 1Active Exploitation · 2026-06-07: 3Active Exploitation · 2026-06-08: 1Active Exploitation · 2026-06-10: 3Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-06-14: 1Active Exploitation · 2026-06-16: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-09-02: 1Patch / Workaround · 2026-05-20: 4Patch / Workaround · 2026-05-21: 21Patch / Workaround · 2026-05-22: 7Patch / Workaround · 2026-05-24: 3Patch / Workaround · 2026-05-25: 2Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-28: 1Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-02: 3Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-05: 2Patch / Workaround · 2026-06-07: 5Patch / Workaround · 2026-06-10: 1Patch / Workaround · 2026-06-16: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-05-20: 4Technical Details · 2026-05-21: 26Technical Details · 2026-05-22: 8Technical Details · 2026-05-24: 3Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-01: 2Technical Details · 2026-06-02: 1Technical Details · 2026-06-03: 2Technical Details · 2026-06-07: 3Technical Details · 2026-06-10: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-16: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-06: 105-2005-2405-2705-3106-0306-0706-1106-1606-2907-0709-28
Signal classification6 categories
Active Exploitation
6058.3%
Patch
1918.4%
General
1211.7%
Disclosure
87.8%
PoC
32.9%
Exploit
11.0%
Referenced assets67 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-206
Active Exploitation3General2Patch1
2026-05-2138
Active Exploitation27Disclosure2Exploit1General2Patch6
2026-05-2211
Active Exploitation7Disclosure1Patch3
2026-05-245
Disclosure2General1Patch2
2026-05-252
Active Exploitation1Patch1
2026-05-261
Patch1
2026-05-271
General1
2026-05-282
Active Exploitation1General1
2026-05-291
Active Exploitation1
2026-05-311
General1
2026-06-013
General2Patch1
2026-06-024
Active Exploitation3Disclosure1
2026-06-032
Active Exploitation2
2026-06-052
Active Exploitation2
2026-06-061
Active Exploitation1
2026-06-076
Active Exploitation1Disclosure1Patch4
2026-06-081
Active Exploitation1
2026-06-104
Active Exploitation3General1
2026-06-111
General1
2026-06-121
Active Exploitation1
2026-06-141
Active Exploitation1
2026-06-161
Active Exploitation1
2026-06-171
PoC1
2026-06-241
Active Exploitation1
2026-06-291
PoC1
2026-06-301
Active Exploitation1
2026-07-061
PoC1
2026-07-071
Disclosure1
2026-07-121
Active Exploitation1
2026-09-021
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Microsoft warns two Defender vulnerabilities are being actively exploited in the wild. https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html 🔸 CVE-2026-41091 could allow attackers to gain SYSTEM privileges locally. 🔸 CVE-2026-45498 is a denial-of-service flaw impacting Defender. CISA added both to KEV with a June 3, 2026 patch deadline.

    Post summary

    Microsoft warns that two Defender CVEs are actively exploited, with a KEV patch deadline scheduled for June 3, 2026.

    3122435710233.9K
    1.9M followersView on X
  • Tim@Unrealisedd
    PoC

    Microsoft patched UnDefend (CVE-2026-45498) back in May but all they did was block one locking method. The actual root cause, permissive DACLs on Defender's signature files, is still wide open. Any standard user can freeze signature updates with a single CreateFileW call. That's not a fix. Huge credit to @ChaoticEclipse0 for the original UnDefend research that inspired this. Their work exposed a fundamental design flaw in how Defender protects its own files and Microsoft's patch proved they didn't fully understand it. PoC + full writeup: https://github.com/Unrealisedd/exploitarium/tree/main/defender-signature-lock-bypass

    Post summary

    The post highlights that Microsoft’s patch for CVE‑2026‑45498 is inadequate, provides a PoC repository, and explains the technical root cause involving permissive DACLs on Defender files.

    1162553118.3K
    43 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    مايكروسفت تهدد برفع قضايا على الباحث الامني Nightmare Eclipse بعد مابهدلهم ونشر 6 ثغرات 0day (RedSun) CVE-2026-41091 (UnDefend) CVE-2026-45498 (BlueHammer) CVE-2026-33825 (YellowKey) CVE-2026-45585 (GreenPlasma) (MiniPlasma) مو من صالحهم يعادون مجتمع الباحثين بهالطريقه https://t.co/bFoufGGRYW

    Post summary

    The tweet reports that Microsoft threatens to sue security researcher Nightmare Eclipse after the researcher disclosed six zero-day vulnerabilities (CVE-2026-41091, CVE-2026-45498, CVE-2026-33825, CVE-2026-45585 and two unnamed).

    581453522.4K
    50.0K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Microsoft alerta sobre dos vulnerabilidades de Defender que están siendo explotadas Escalada de privilegios (CVE-2026-41091) y denegación de servicio (CVE-2026-45498) https://blog.elhacker.net/2026/05/microsoft-alerta-sobre-dos.html

    Post summary

    Microsoft warns that two Defender vulnerabilities—CVE‑2026‑41091 (privilege escalation) and CVE‑2026‑45498 (denial of service)—are currently being exploited in the wild.

    115058113.2K
    141.0K followersView on X
  • Fabian Bader@fabian_bader
    Patch

    The latest Windows Antivirus Platform 4.18.26040.7 and Engine 1.1.26040.8 fix three security issues, two of them already exploited and publicly available... CVE-2026-41091 (RedSun) CVE-2026-45498 (UnDefend) CVE-2026-45584 (???) #MDE #MDAV https://t.co/yDSi6HaTZK

    Post summary

    Microsoft announced a new antivirus patch that addresses three CVEs, with two already exploited in the wild.

    39123614.2K
    10.4K followersView on X
  • Azubuike Ibe@ai_dev_official
    Active Exploitation

    Two Microsoft Defender vulnerabilities were disclosed yesterday. Both are already being exploited. CVE-2026-41091 is a local privilege escalation flaw caused by improper link resolution. An attacker with local access can use it to gain elevated system privileges. Microsoft and CISA have both confirmed active exploitation in the wild. CVE-2026-45498 is a Denial-of-Service vulnerability targeting Defender components. Also confirmed exploited. Also added to CISA’s Known Exploited Vulnerabilities catalog on May 20. These are not theoretical. They are in the KEV list. That means attackers are using them now. The exploitation scope is still being assessed. No major vendor has published confirmed telemetry on large-scale chained campaigns yet. But the window between disclosure and weaponisation has been closing for years. Waiting for a full incident report before patching is how organisations end up in the incident report. Here is what you should do today. Update your Defender platform and engine versions immediately. Check your local admin and service account permissions. Enable behavioral monitoring and EDR telemetry if it is not already on. Audit your Defender exclusion policies. Watch for abnormal Defender service activity. Default Defender configurations were not built for a threat landscape where CVEs hit the KEV list the day after disclosure. Layered controls are not optional in 2026. My name is Azubuike Ibe and I write about threats that are already moving before most people have read the advisory. Share this with a developer or sysadmin on your team who has not patched yet. It may save them a very bad week. #Cybersecurity #MicrosoftDefender #WindowsSecurity #DevSecOps #AppSec

    Post summary

    The post reports that two Microsoft Defender vulnerabilities (LLPE and DoS) are actively being exploited in the wild and urges immediate patching and security hardening.

    03077137
    1.5K followersView on X
  • ChainPatrol@ChainPatrol
    Patch

    🚨 Microsoft patched two Defender zero-days (CVE-2026-41091 & CVE-2026-45498) — one escalates a low-privileged attacker to SYSTEM level (local exploit, no user interaction needed), the other causes a denial-of-service. Both actively exploited; CISA added both to its KEV catalog. Most systems auto-update, but verify your Defender engine is on 1.1.26040.8+. https://www.bleepingcomputer.com/news/security/microsoft-warns-of-new-defender-zero-days-exploited-in-attacks/

    Post summary

    Microsoft patched two Defender zero‑day vulnerabilities, CVE‑2026‑41091 (privilege escalation) and CVE‑2026‑45498 (DoS); both are actively exploited, and users should confirm their Defender engine is version 1.1.26040.8 or newer.

    040101321
    5.1K followersView on X
  • yousukezan@yousukezan
    PoC

    Microsoft Defenderのゼロデイ脆弱性「RoguePlanet」が公開され、SYSTEM権限の取得が可能になることが明らかになった。Microsoftは現在修正プログラムを開発中で、CVE-2026-50656として追跡している。 Microsoftはこの問題を権限昇格の脆弱性と説明しており、CVSSスコアは7.8。Microsoft Malware Protection Engineに存在し、同社は「高品質なセキュリティ更新プログラムの提供に向けて作業している」としている。 RoguePlanetは研究者のChaotic Eclipse(Nightmare-Eclipse)が先週公開した。公開されたPoCは競合状態(Race Condition)を悪用するもので、成功するとSYSTEM権限のシェルを取得できる。研究者によると成功率は環境によって異なるが、一部環境では100%の成功率を確認したという。 さらに研究者は、リアルタイム保護の有効・無効に関係なくPoCが動作すると説明しており、Defenderのパッシブモードでも影響する可能性があるとしている。 Microsoftは公開当初から脆弱性の有効性と影響範囲を調査していた。Chaotic Eclipseが公開したDefender関連の脆弱性は今回で4件目となり、過去のBlueHammer(CVE-2026-33825)、UnDefend(CVE-2026-45498)、RedSun(CVE-2026-41091)はすでに修正されている。 https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html

    Post summary

    Microsoft Defender vulnerability CVE-2026-50656 has a publicly disclosed PoC demonstrating SYSTEM privilege escalation through a race condition; Microsoft is developing a fix, but no evidence of active exploitation exists.

    020821.4K
    14.8K followersView on X
  • piyokango@piyokango
    Patch

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/20追加) 🛡️No.1594 CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:バッファエラー (CWE-119) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Microsoft Windows の Server service において、細工された RPC リクエストによりパス正規化処理中にオーバーフローが発生し、リモートから任意のコード実行をされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Windows Server service が稼働していること。 ・攻撃者が対象へネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・リモートで任意のコードを実行される ・影響を受けるシステムを完全に制御される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2008-4250 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2008/ms08-067 🛡️No.1595 CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability =================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:NULL バイトまたは NULL キャラクタの不適切な無害化 (CWE-158) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft DirectX の DirectShow に含まれる QuickTime Movie Parser Filter において、細工された QuickTime メディアファイルにより任意のコード実行をされる恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける DirectX/Windows 環境が稼働していること。 ・攻撃者が細工された QuickTime メディアファイルを対象へ到達させること。 ・利用者が当該ファイルを処理すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・細工されたメディアファイルの処理によりシステムが侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み。Microsoft は、当時このエクスプロイトコードを使用した限定的なアクティブ攻撃を認識していると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-1537 https://learn.microsoft.com/ja-jp/security-updates/securityadvisories/2009/971778 🛡️No.1596 CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability ==================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:ヒープベースのバッファオーバーフロー (CWE-122) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Adobe Reader および Acrobat において、細工された PDF の処理によりメモリ破損が発生し、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Adobe Reader または Acrobat が稼働していること。 ・攻撃者が細工された PDF ファイルを対象へ到達させること。 ・利用者が当該 PDF を開くこと。 ✅悪用時影響 ・リモートで任意のコードを実行される ・PDF 処理時のメモリ破損によりシステムを侵害される✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-3459 http://blogs.adobe.com/psirt/2009/10/adobe_reader_and_acrobat_issue_1.html 🛡️No.1597 CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability ✅概要 ・深刻度:重要 8.8 (CVSS Base) / NVD ・種別:解放済みメモリの使用 (CWE-416) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Internet Explorer 6/7/8 における use-after-free の脆弱性が存在。削除済みオブジェクトに関連するポインタへアクセスさせることで、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Internet Explorer が稼働していること。 ・攻撃者が細工された Web ページへ利用者を誘導できること。 ・利用者が当該 Web ページを表示すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・メモリ内オブジェクトの不適切な取り扱いによりブラウザ経由で侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2010-0249 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2010/ms10-002 🛡️No.1598 CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability ✅概要 ・深刻度:重要 8.8 (CVSS Base) / CISA-ADP ・種別:解放済みメモリの使用 (CWE-416) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Internet Explorer の Peer Objects component(iepeers.dll)における use-after-free の脆弱性が存在。オブジェクト削除後の無効ポインタ参照により、リモートで任意コードを実行される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・影響を受ける Internet Explorer が稼働していること。 ・攻撃者が細工された Web ページへ利用者を誘導できること。 (Microsoft Learn) ・利用者が当該 Web ページを表示すること。 ✅悪用時影響 ・リモートで任意のコードを実行される ・オブジェクト解放後の不正参照によりブラウザ経由で侵害される ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2010-0806 https://learn.microsoft.com/ja-jp/security-updates/securitybulletins/2010/ms10-018 🛡️No.1599 CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability =================================== ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Microsoft Corporation ・種別:リンク解釈の問題 (CWE-59) ・CVSS:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Microsoft Defender における link following の脆弱性が存在。認証済みの攻撃者により、ローカル上で権限昇格される恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:高 ✅攻撃前提条件 ・影響を受ける Microsoft Malware Protection Engine が稼働していること。 ・攻撃者がローカルで認証済み権限を有していること。 ・ローカルで悪用可能な環境であること。 ✅悪用時影響 ・ローカルで権限昇格される ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-41091 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091 🛡️No.1600 CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / NVD ・種別:リソースの枯渇 (CWE-400) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Microsoft Defender におけるサービス運用妨害の脆弱性が存在。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・影響を受ける Microsoft Defender Antimalware Platform が稼働していること。 ・NVD 採点上、攻撃者がネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・サービス運用妨害により可用性へ高い影響が生じる ・Microsoft Defender の動作停止または機能阻害につながる ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-45498 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498 https://www.cisa.gov/news-events/alerts/2026/05/20/cisa-adds-seven-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces seven CVEs added to CISA's catalog, detailing their severity, technical nature, and linking to vendor patches, with a note that CVE-2009-1537 has confirmed active exploitation.

    020626.3K
    43.9K followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    【Microsoft Defenderの実悪用ゼロデイ2件、CISA KEVに追加】 Microsoft DefenderのCVE-2026-41091とCVE-2026-45498が実悪用されています。 前者はローカル権限昇格によりSYSTEM権限取得につながる可能性があり、後者はDefenderのDoSを引き起こす脆弱性です。 初期侵入済み端末で悪用されると、防御機能の妨害、資格情報窃取、横展開、ランサムウェア展開までの足場になり得ます。 自動更新前提の環境でも、隔離端末、VDI、長期間停止端末、管理外端末では更新漏れを確認すべきです。 Defenderのエンジン/Platformバージョン、保護更新失敗、SYSTEM権限での不審プロセス生成を重点的に確認してください。 #MicrosoftDefender #CVE #KEV #ZeroDay #WindowsSecurity #SOC #ThreatHunting https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/

    Post summary

    Microsoft Defender CVE-2026-41091 and CVE-2026-45498 are actively exploited, exposing systems to privilege escalation, DoS, credential theft, lateral movement, and ransomware; defenders should verify update status and monitor for suspicious processes.

    00032503
    3.7K followersView on X
  • Threat Intelligence@threatintel
    Disclosure

    #ThreatProtection #UnDefend #CVE-2026-45498 - Microsoft Defender Denial of Service #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/undefend-cve-2026-45498-microsoft-defender-denial-of-service-vulnerability

    Post summary

    The post announces the Microsoft Defender denial‑of‑service vulnerability CVE‑2026‑45498 and links to a Symantec protection bulletin, but provides no PoC, exploit code, or evidence of active exploitation.

    010211.7K
    115.1K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    Acaba de confirmarse: Microsoft Defender tiene dos vulnerabilidades explotadas en el mundo real, identificadas como CVE-2026-41091 y CVE-2026-45498. Microsoft Defender es el producto afectado. La vulnerabilidad CVE-2026-41091 permite la elevación de privilegios local. Estas vulnerabilidades pueden ser explotadas por atacantes. Es importante que los administradores de sistemas revisen sus configuraciones de seguridad. ¿Hay parche? No se menciona. ¿Estás en riesgo? Revisa esto: asegúrate de que tus sistemas estén actualizados. #CiberseguridadMX #Ransomware #CVE https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/

    Post summary

    Microsoft Defender versions have two CVEs (CVE-2026-41091 and CVE-2026-45498) that are currently being exploited in the wild, with CVE-2026-41091 enabling local privilege escalation; no patch or workaround is mentioned.

    0102181
    460 followersView on X
  • Dirt Jordan@techfusionjb
    General

    @DarkWebInformer CVE-2026-45498 is UnDefend. If that's accurate, this isn't a bug report. It's a career-ending move. Tells me everything I need to know about disclosure politics today.

    Post summary

    The tweet comments on the potential career impact of CVE-2026-45498 being labeled "UnDefend", highlighting concerns around disclosure politics without providing technical or operational details.

    000301.2K
    93 followersView on X
  • Clone Systems@CloneSystemsInc
    Active Exploitation

    Vulnerability Alert — Microsoft Defender Microsoft disclosed two actively exploited Defender vulnerabilities now added to CISA’s KEV catalog. • CVE-2026-41091 (CVSS 7.8) — Privilege escalation to SYSTEM • CVE-2026-45498 (CVSS 4.0) — Denial of Service Organizations should verify Defender platform updates and ensure systems are running the latest protection engine versions. #CyberSecurity #VulnerabilityAlert #MicrosoftDefender #PatchNow

    Post summary

    Microsoft has identified two actively exploited Microsoft Defender CVEs, added to CISA’s KEV catalog, and urges organizations to verify updates and run the latest protection engine versions to mitigate the risk.

    0003073
    256 followersView on X
  • Upwind Security MDR@UpwindMDR
    Active Exploitation

    🚨 Microsoft reports two actively exploited vulnerabilities in Microsoft Defender (CVE-2026-41091)(CVE-2026-45498). (CVE-2026-41091) Microsoft Defender Privilege EscalationImproper link resolution before file access ('link following') allows an authorized local attacker to elevate privileges and gain SYSTEM level access. (CVE-2026-45498) Microsoft Defender Denial of Service A denial-of-service vulnerability that can disrupt Microsoft Defender operations. Both vulnerabilities are actively exploited in the wild and added to CISA KEV catalog. Fixed in Microsoft Defender Antimalware Platform versions 1.1.26040.8 and 4.18.26040.7. Affected: Microsoft Defender (all active installations)

    Post summary

    Microsoft announced two actively exploited vulnerabilities in Defender (CVE‑2026‑41091 and CVE‑2026‑45498), detailing privilege‑escalation and denial‑of‑service flaws, confirming wild exploitation, and providing patch versions.

    00030113
    255 followersView on X
  • Help Net Security@helpnetsecurity
    Active Exploitation

    Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) - https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/ - @Microsoft @MsftSecIntel #MicrosoftDefender #Vulnerability #VulnerabilityDisclosure #Windows #Cybersecurity #CybersecurityNews https://t.co/MPKZmjCuBz

    Post summary

    The tweet reports that Microsoft Defender’s CVE‑2026‑41091 and CVE‑2026‑45498 are being actively exploited in the wild, but provides no PoC, exploit code, patch, or technical details.

    01020388
    60.1K followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Patch

    🚨 #Vulnerabilidad crítica de escalada de privilegios en #Microsoft #Defender (CVE-2026-41091 / CVE-2026-45498) (+MITIGACIÓN) https://www.newstecnicas.com/2026/05/vulnerabilidad-critica-de-escalada-de.html

    Post summary

    The tweet announces two critical privilege‑escalation CVEs for Microsoft Defender with a note that mitigations are available, but it lacks technical details or exploit references.

    0101040
    1.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 #Microsoft Defender, Denial of Service, #CVE-2026-45498 (Medium) https://dailycve.com/microsoft-defender-denial-of-service-cve-2026-45498-medium/

    Post summary

    The tweet announces the discovery of CVE-2026-45498, a Medium‑severity denial‑of‑service flaw in Microsoft Defender, but contains no PoC, exploit details, or patch information.

    0101069
    220 followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Microsoft patches two Defender zero-days (CVE-2026-41091, CVE-2026-45498) actively exploited for privilege escalation and DoS. CISA orders federal agencies to patch by June 3rd. #DFIR_Radar https://t.co/AfAgZSjoIE

    Post summary

    Microsoft has released patches for two Defender zero‑days (CVE‑2026‑41091 and CVE‑2026‑45498) that were actively exploited for privilege escalation and denial‑of‑service; CISA mandates federal agencies to remediate by June 3rd.

    10010181
    1.8K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) https://www.helpnetsecurity.com/2026/05/21/microsoft-defender-vulnerabilities-cve-2026-41091-cve-2026-45498/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The article reports that Microsoft Defender CVEs 2026-41091 and 2026-45498 are being actively exploited in the wild, though it lacks details on patches or technical specifics.

    00020419
    194.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdefender_antimalware_platform---

Explore more