<< Back
CVE Number Vulnerability Product Severity Date
CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability Microsoft Defender Important 29-05-2026

Technical Information

An authorized attacker with local low-privileged access could exploit an improper link resolution (link-following) flaw in Microsoft Defender to perform unauthorized file operations and elevate privileges to NT AUTHORITY\SYSTEM on the affected system.

Patch release date: May 19, 2026
Further information on this vulnerability is available at : CVE-2026-41091

Affected Software

Microsoft Malware Protection Engine