Microsoft Issues Patches for Two Exploited Defender Vulnerabilities
Patch Microsoft Defender to the latest update immediately.
Patch Microsoft Defender to the latest update immediately.
Summary
Microsoft has released security updates for two zero‑day vulnerabilities that were already being exploited in the wild. The first flaw, CVE‑2026‑41091, is a privilege‑escalation bug in the Malware Protection Engine (versions 1.1.26030.3008 and earlier) that allows attackers to gain SYSTEM rights by manipulating link resolution before file access. The second flaw, CVE‑2026‑45498, is a denial‑of‑service vulnerability in the Defender Antimalware Platform (4.18.26030.3011 and earlier) that can crash unpatched Windows devices when triggered by malicious input.
These weaknesses were discovered by Microsoft’s security team and immediately added to the company’s known exploited vulnerabilities catalog. The patches, version 1.1.26040.8 for the Malware Protection Engine and 4.18.26040.7 for the Antimalware Platform, are now available through the standard Windows Update mechanism. Microsoft notes that the default configuration will keep malware definitions and the platform up to date automatically, but users are advised to verify that the Antimalware ClientVersion matches or exceeds the patched version by checking Windows Security → Virus & threat protection → Protection Updates → Check for updates.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has responded by issuing Binding Operational Directive 22‑01, which orders all federal civilian agencies to apply the patches by June 3. The directive underscores the seriousness of the vulnerabilities, noting that the privilege‑escalation flaw could allow attackers to execute arbitrary code with SYSTEM privileges, while the denial‑of‑service flaw could disrupt critical services on unpatched machines.
For organizations and individuals, the key takeaway is to ensure that Microsoft Defender is running the latest version and that automatic updates are enabled. Failure to patch could expose systems to attackers who can either take full control of a device or render it inoperable. The incident highlights the ongoing arms race between software vendors and threat actors, and the importance of rapid patch deployment in maintaining the security of the Windows ecosystem.
Key changes
- CVE‑2026‑41091 is a privilege escalation flaw in Defender.
- CVSS score 7.8.
- Denial‑of‑service vulnerability also with CVSS 7.8.
- Exploits improper link resolution before file access.
- Active exploitation reported in the wild.
- Microsoft issued a patch for both issues.