Critical Microsoft Defender SmartScreen Zero-Day Actively Exploited
Key Takeaways Two critical vulnerabilities, CVE‑2026‑41091 and CVE‑2026‑45498, have been discovered in Microsoft Defender. Both flaws are actively being exploited in the wild, allowing local...
Key Takeaways
- Two critical vulnerabilities, CVE‑2026‑41091 and CVE‑2026‑45498, have been discovered in Microsoft Defender.
- Both flaws are actively being exploited in the wild, allowing local attackers to elevate privileges to SYSTEM or cause a denial of service.
- The vulnerabilities impact core Microsoft Defender components across all supported Windows versions.
- Microsoft has released patches, with automatic updates typically addressing the issues without manual intervention.
- CISA has added both CVEs to its Known Exploited Vulnerabilities Catalog, mandating remediation for U.S. federal agencies by June 3, 2026.
Microsoft Defender, the default endpoint protection solution for Windows, is currently facing active exploitation from two recently disclosed zero-day vulnerabilities. These critical flaws could allow local attackers to escalate privileges to the highest SYSTEM level or trigger a denial of service, potentially undermining security across Windows environments.
Table Of Content
The vulnerabilities, identified as CVE‑2026‑41091 (Elevation of Privilege) and CVE‑2026‑45498 (Denial of Service), were publicly disclosed on May 19, 2026. They affect fundamental components of Microsoft Defender, impacting all currently supported Windows operating system versions.
Microsoft Defender Elevation of Privilege Vulnerability
Tracked as CVE‑2026‑41091, this “Important” severity flaw enables privilege escalation due to an improper link resolution mechanism in Microsoft Defender’s scanning engine. Specifically, the vulnerability arises from “link following” behavior before file access, which an attacker can manipulate.
An authenticated local attacker could exploit this weakness by crafting malicious links or junctions. Defender’s scanning logic would then follow these crafted paths, operating on attacker-controlled directories and ultimately granting the attacker SYSTEM-level privileges. Microsoft has confirmed active exploitation of this vulnerability, noting its “Exploitation Detected” status on its exploitability index.
Successful exploitation of CVE‑2026‑41091 provides threat actors with significant control over compromised systems. This includes the ability to disable or tamper with security software, deploy persistent malware, access sensitive data, and create new accounts with elevated privileges, thereby amplifying the impact of any initial breach. The vulnerability is present in Microsoft Malware Protection Engine versions up to 1.1.26030.3008 and is resolved in version 1.1.26040.8 and later.
Even systems where Defender is intentionally disabled may still register as vulnerable during security scans. This occurs because the affected binaries and versioned components often remain on disk, even if the security configuration itself is not exploitable in practice.
Microsoft Defender Denial of Service Vulnerability
The second critical flaw, CVE‑2026‑45498, is a Denial-of-Service vulnerability impacting the Microsoft Defender Antimalware Platform. Like the privilege escalation bug, this vulnerability has been publicly disclosed and is actively exploited, confirmed by Microsoft’s “Exploitation Detected” status.
By leveraging this platform-level weakness, attackers can potentially crash or disrupt Defender’s core protection functionalities. Such an outage creates a critical window for subsequent attacks, allowing threat actors to bypass defenses, establish stealthy persistence, or execute further malicious activities without immediate detection. The last affected platform version is 4.18.26030.3011, with the fix implemented in version 4.18.26040.7. Similar to the engine vulnerability, systems with disabled Defender might still show up as vulnerable in scan reports due to residual binaries, even if not actively exploitable.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has taken the significant step of adding both CVE‑2026‑41091 and CVE‑2026‑45498 to its Known Exploited Vulnerabilities (KEV) Catalog. This inclusion underscores the confirmed in-the-wild exploitation of both flaws. Under Binding Operational Directive (BOD) 22‑01, Federal Civilian Executive Branch (FCEB) agencies are mandated to remediate these vulnerabilities on all Windows endpoints and servers by June 3, 2026, providing a two-week window from their KEV listing on May 20.
What You Should Do
- Verify that the Microsoft Defender engine version is at least 1.1.26040.8 and the Antimalware Platform version is at least 4.18.26040.7 on all Windows endpoints and servers.
- Utilize the Windows Security application: navigate to “Virus & threat protection,” then “Protection updates,” and select “Check for updates” to manually initiate an update if needed.
- Confirm the Antimalware Client version in Windows Security → Settings → About meets or exceeds the specified fixed versions.
- Ensure that your organization’s update distribution pipelines for Microsoft Defender are functioning correctly and that updates are being consistently delivered and applied.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.