Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-33825

Published 2026-04-14
Updated last month
Vendor/s
Microsoft
Product/s
Defender
Version/s
* > 4.18.26030.3011
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
7.8
/ 10
High
Severity Details
Base score
7.8 High
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-33825 is a high-severity (7.8) privilege escalation flaw in Microsoft Defender actively exploited in the wild. Update to version 4.18.26030.3011.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
defender_antimalware_platform * 4.18.26030.3011 vulnerable

Related weakness (CWE)

CWE-1220

Remediation plan

1

Apply official patches

Download and install the latest security updates for Microsoft Defender via Windows Update or the Microsoft Update Catalog to address the access control flaw.

2

Update affected systems

Ensure the Microsoft Defender Antimalware Platform is updated to version 4.18.26030.3011 or later to remediate the vulnerability across all endpoints.

3

Restrict access

Enforce the principle of least privilege (PoLP) to limit local user permissions, reducing the surface area for attackers to attempt local privilege escalation.

4

Monitor for exploitation

Audit system logs for unusual service permission changes or unexpected processes spawned by Defender-related components, which may indicate an exploitation attempt.

Detection Guidance

To detect potential exploitation of CVE-2026-33825, monitor Windows Event Logs for Event ID 4673 (Sensitive Privilege Use) or Event ID 4688 (Process Creation) involving Defender binaries. Look for unauthorized modifications to registry keys or file permissions associated with the Antimalware Platform. Security teams should also deploy EDR signatures that flag suspicious local privilege escalation patterns targeting core security services.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management