CVE-2026-41091 & CVE-2026-45498: Microsoft Defender Zero-Days Under Active Exploitation

Technical root cause for the dual Microsoft Defender zero-days exploited to evade AV scanning and achieve privilege escalation.

CVE-2026-41091 & CVE-2026-45498: Microsoft Defender Zero-Days Under Active Exploitation
📌
Security Roundup Series: Week of May 21, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-41091 / 45498 Severity: CVSS 8.4 Status: ⚠️ Actively Exploited EDR Bypass Zero-Days Target Component: Microsoft Defender for Endpoint

CISA added two Microsoft Defender zero-days to its Known Exploited Vulnerabilities catalog on May 20, 2026, with a June 3 federal remediation deadline. Both CVE-2026-41091 (local privilege escalation to SYSTEM) and CVE-2026-45498 (denial of service) are confirmed actively exploited in the wild.


CVE-2026-41091: Local Privilege Escalation (CVSS 7.8)

The vulnerability resides in the Microsoft Malware Protection Engine (MMPE) — a classic link-following (symlink) vulnerability (CWE-59). When Defender processes a file via a symbolic link, it fails to adequately validate the target path before accessing it with SYSTEM-level privileges.

Exploitation path:

  1. An authenticated low-privilege local user creates a symbolic link pointing from a path MMPE scans to a protected system resource.
  2. The Defender scan engine, running as SYSTEM, follows the symlink without adequate target validation.
  3. The engine reads or writes to the linked target with SYSTEM privileges.
  4. The attacker leverages the SYSTEM-level file operation for privilege escalation — e.g., replacing a DLL loaded by a SYSTEM process or writing to a SYSTEM-only location.

Affected: Microsoft Malware Protection Engine prior to 1.1.26040.8
Fixed: MMPE 1.1.26040.8 (auto-updated via Windows Update)


CVE-2026-45498: Denial of Service (CVSS 6.5)

CVE-2026-45498 allows an attacker to render Microsoft Defender non-functional, preventing file scanning and alert generation. Particularly dangerous when chained: an attacker can first blind Defender using CVE-2026-45498, then execute malicious payloads that would otherwise be detected. The vulnerability causes MMPE to crash or enter an unresponsive state when processing specially crafted input, and is not self-recovering without a manual service restart.

Affected: Microsoft Malware Protection Engine prior to 1.1.26040.8
Fixed: MMPE 1.1.26040.8


CISA KEV: The May 20 Batch

Alongside the two Defender flaws, CISA added five additional vulnerabilities to the KEV catalog on May 20 — four are extremely old Windows and browser vulnerabilities (2008–2010) still being actively exploited:

  • CVE-2008-4250: Microsoft Windows Server Service buffer overflow (MS08-067 / Conficker) — still exploited in 2026
  • CVE-2009-1537: Microsoft DirectX NULL byte overwrite
  • CVE-2009-3459: Adobe Acrobat and Reader heap-based buffer overflow
  • CVE-2010-0249: Microsoft Internet Explorer use-after-free (Aurora campaign)
  • CVE-2010-0806: Microsoft Internet Explorer use-after-free

The presence of CVE-2008-4250 (MS08-067) on the 2026 KEV list is a stark reminder that unpatched legacy Windows systems remain viable targets.


What to Do

Verify MMPE version immediately:

# PowerShell
Get-MpComputerStatus | Select-Object AMEngineVersion, AMProductVersion
# AMEngineVersion should be 1.1.26040.8 or later

Force update if needed:

Update-MpSignature -UpdateSource MicrosoftUpdateServer

Audit Defender service health across endpoints: Use Intune, SCCM, or GPO to query AMServiceEnabled and AMRunningMode fleet-wide — CVE-2026-45498 exploitation would show Defender in a stopped/non-functional state.

Federal agencies: BOD 22-01 requires FCEB agencies to remediate both CVEs by June 3, 2026. Verify MMPE version is deployed to all endpoints, particularly those with Windows Update deferred or behind air-gapped update infrastructure.

Hunt for symlink abuse: Review Windows Security event logs (Event ID 4663 — Object Access) for unexpected SYSTEM-level access to symbolic links in temp directories or user-writable paths.

→ Back to the Week of May 21 Security Roundup


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther