CVE-2026-33825 is a high-severity (7.8) privilege escalation flaw in Microsoft Defender actively exploited in the wild. Update to version 4.18.26030.3011.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| defender_antimalware_platform | * | 4.18.26030.3011 | vulnerable |
Download and install the latest security updates for Microsoft Defender via Windows Update or the Microsoft Update Catalog to address the access control flaw.
Ensure the Microsoft Defender Antimalware Platform is updated to version 4.18.26030.3011 or later to remediate the vulnerability across all endpoints.
Enforce the principle of least privilege (PoLP) to limit local user permissions, reducing the surface area for attackers to attempt local privilege escalation.
Audit system logs for unusual service permission changes or unexpected processes spawned by Defender-related components, which may indicate an exploitation attempt.
To detect potential exploitation of CVE-2026-33825, monitor Windows Event Logs for Event ID 4673 (Sensitive Privilege Use) or Event ID 4688 (Process Creation) involving Defender binaries. Look for unauthorized modifications to registry keys or file permissions associated with the Antimalware Platform. Security teams should also deploy EDR signatures that flag suspicious local privilege escalation patterns targeting core security services.
Experience superior visibility and a simpler approach to cyber risk management