CVE-2026-45584Disclosure(microsoft / malware_protection_engine)

MEDIUMCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft malware_protection_engine systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • malware_protection_engine

Threat summary

  • Active exploitation appears in 4 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-20); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
malware_protection_engine

Deep dive

Activity timeline9 mentions / 4d
01223Mentions · 2026-05-20: 3Mentions · 2026-05-21: 3Mentions · 2026-06-02: 2Mentions · 2026-06-06: 1Active Exploitation · 2026-05-20: 1Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-06-02: 2Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-06-02: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 2Technical Details · 2026-06-06: 105-2005-2106-0206-06
Signal classification4 categories
Disclosure
333.3%
Active Exploitation
333.3%
General
222.2%
Patch
111.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-203
Disclosure1General1Patch1
2026-05-213
Active Exploitation1Disclosure2
2026-06-022
Active Exploitation2
2026-06-061
General1
Full discourse9 posts
  • Fabian Bader@fabian_bader
    Patch

    The latest Windows Antivirus Platform 4.18.26040.7 and Engine 1.1.26040.8 fix three security issues, two of them already exploited and publicly available... CVE-2026-41091 (RedSun) CVE-2026-45498 (UnDefend) CVE-2026-45584 (???) #MDE #MDAV https://t.co/yDSi6HaTZK

    Post summary

    The tweet announces a Windows Antivirus patch that addresses three CVEs, noting that two of them are already exploited and publicly available, but it does not provide technical exploitation details or specific PoC code.

    39123614.2K
    10.4K followersView on X
  • Nicolas Krassas@Dinosn
    General

    Microsoft Defender Remote Code Execution Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584

    Post summary

    A brief reference to Microsoft Defender Remote Code Execution vulnerability with a link to the MSRC update guide; no additional details on exploitation, patching, or technical specifics are supplied.

    030941.6K
    158.6K followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 5.19 Microsoft Defender のリモートでコードが実行される脆弱性 CVE-2026-45584 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45584

    Post summary

    The post announces a remote code execution vulnerability in Microsoft Defender (CVE‑2026‑45584) and links to Microsoft's update guide, but provides no PoC, exploit, or patch details.

    10100107
    85 followersView on X
  • B2B Cyber Security.de@B2bCyber
    Active Exploitation

    Updates prüfen: Defender-Lücken wurden aktiv attackiert https://ift.tt/cbuoKiw Microsoft hat drei Sicherheitslücken in Defender geschlossen, die Unternehmen prüfen sollten: Betroffen sind CVE-2026-41091, CVE-2026-45584 und CVE-2026-45498. Zwei der Schwachstellen wurden laut …

    Post summary

    Microsoft has patched three Defender vulnerabilities after reports of active exploitation, and customers should check for updates.

    0001040
    1.7K followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-45584 影響: リモートでコードが実行される 最大深刻度: 緊急 CVSS:3.1 8.1 / 7.1 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: https://x.com/kawn2020/status/2057405197044126084

    Post summary

    CVE-2026-45584 is a remote code execution vulnerability with high CVSS and emergency severity, but no PoC, exploit code, or active exploitation has been reported, and no patch or workaround is mentioned.

    1000055
    85 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-45584: Microsoft Defender Heap-Based Buffer Overflow - What It Means for Your Business and How to Respond https://hubs.li/Q04kp2Y00

    Post summary

    The article provides a high‑level overview of CVE-2026-45584, a heap‑based buffer overflow in Microsoft Defender, without detailing PoCs, exploits, or patches.

    0000029
    32 followersView on X
  • B2B Cyber Security.de@B2bCyber
    Active Exploitation

    https://ift.tt/WXFIuJ0 Check for updates: Defender vulnerabilities were actively exploited. Microsoft has patched three security vulnerabilities in Defender that organizations should check: CVE-2026-41091, CVE-2026-45584, and CVE-2026-45498. Two of the vulnerabilities have r… https://t.co/MXUx8w7iN9

    Post summary

    The message warns that Defender vulnerabilities were actively exploited and highlights that Microsoft has released patches for CVE‑2026‑41091, CVE‑2026‑45584, and CVE‑2026‑45498, urging organizations to verify they have applied them.

    0000038
    1.7K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Microsoft Malware Protection Engine (CVE-2026-45584) https://vuldb.com/vuln/364878/cti

    Post summary

    The post alerts to elevated malicious activity targeting Microsoft Malware Protection Engine CVE‑2026‑45584, indicating possible in‑the‑wild exploitation but lacking any PoC, patch, or technical detail.

    0000078
    2.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Microsoft Malware Protection Engine (CVE-2026-45584) https://vuldb.com/vuln/364878

    Post summary

    The message reports the disclosure of CVE-2026-45584 in Microsoft Malware Protection Engine but provides no PoC, exploit details, patch information, or technical depth.

    0000095
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftmalware_protection_engine---

Explore more