CVE-2026-41091 & CVE-2026-45498: Microsoft Defender Zero-Days Under Active Exploitation
Technical root cause for the dual Microsoft Defender zero-days exploited to evade AV scanning and achieve privilege escalation.
CVE-2026-41091 / 45498
Severity: CVSS 8.4
Status: ⚠️ Actively Exploited EDR Bypass Zero-Days
Target Component: Microsoft Defender for Endpoint
CISA added two Microsoft Defender zero-days to its Known Exploited Vulnerabilities catalog on May 20, 2026, with a June 3 federal remediation deadline. Both CVE-2026-41091 (local privilege escalation to SYSTEM) and CVE-2026-45498 (denial of service) are confirmed actively exploited in the wild.
CVE-2026-41091: Local Privilege Escalation (CVSS 7.8)
The vulnerability resides in the Microsoft Malware Protection Engine (MMPE) — a classic link-following (symlink) vulnerability (CWE-59). When Defender processes a file via a symbolic link, it fails to adequately validate the target path before accessing it with SYSTEM-level privileges.
Exploitation path:
- An authenticated low-privilege local user creates a symbolic link pointing from a path MMPE scans to a protected system resource.
- The Defender scan engine, running as SYSTEM, follows the symlink without adequate target validation.
- The engine reads or writes to the linked target with SYSTEM privileges.
- The attacker leverages the SYSTEM-level file operation for privilege escalation — e.g., replacing a DLL loaded by a SYSTEM process or writing to a SYSTEM-only location.
Affected: Microsoft Malware Protection Engine prior to 1.1.26040.8
Fixed: MMPE 1.1.26040.8 (auto-updated via Windows Update)
CVE-2026-45498: Denial of Service (CVSS 6.5)
CVE-2026-45498 allows an attacker to render Microsoft Defender non-functional, preventing file scanning and alert generation. Particularly dangerous when chained: an attacker can first blind Defender using CVE-2026-45498, then execute malicious payloads that would otherwise be detected. The vulnerability causes MMPE to crash or enter an unresponsive state when processing specially crafted input, and is not self-recovering without a manual service restart.
Affected: Microsoft Malware Protection Engine prior to 1.1.26040.8
Fixed: MMPE 1.1.26040.8
CISA KEV: The May 20 Batch
Alongside the two Defender flaws, CISA added five additional vulnerabilities to the KEV catalog on May 20 — four are extremely old Windows and browser vulnerabilities (2008–2010) still being actively exploited:
- CVE-2008-4250: Microsoft Windows Server Service buffer overflow (MS08-067 / Conficker) — still exploited in 2026
- CVE-2009-1537: Microsoft DirectX NULL byte overwrite
- CVE-2009-3459: Adobe Acrobat and Reader heap-based buffer overflow
- CVE-2010-0249: Microsoft Internet Explorer use-after-free (Aurora campaign)
- CVE-2010-0806: Microsoft Internet Explorer use-after-free
The presence of CVE-2008-4250 (MS08-067) on the 2026 KEV list is a stark reminder that unpatched legacy Windows systems remain viable targets.
What to Do
Verify MMPE version immediately:
# PowerShell
Get-MpComputerStatus | Select-Object AMEngineVersion, AMProductVersion
# AMEngineVersion should be 1.1.26040.8 or laterForce update if needed:
Update-MpSignature -UpdateSource MicrosoftUpdateServerAudit Defender service health across endpoints: Use Intune, SCCM, or GPO to query AMServiceEnabled and AMRunningMode fleet-wide — CVE-2026-45498 exploitation would show Defender in a stopped/non-functional state.
Federal agencies: BOD 22-01 requires FCEB agencies to remediate both CVEs by June 3, 2026. Verify MMPE version is deployed to all endpoints, particularly those with Windows Update deferred or behind air-gapped update infrastructure.
Hunt for symlink abuse: Review Windows Security event logs (Event ID 4663 — Object Access) for unexpected SYSTEM-level access to symbolic links in temp directories or user-writable paths.
→ Back to the Week of May 21 Security Roundup