Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-41091

Published 2026-05-20
Updated last month
Vendor/s
Microsoft
Product/s
Defender
Version/s
1.1.26030.3008 > 1.1.26040.8
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
7.8
/ 10
High
Severity Details
Base score
7.8 High
Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-41091 is a high-severity local privilege escalation flaw in Microsoft Defender's Malware Protection Engine, currently under active exploitation.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
malware_protection_engine 1.1.26030.3008 1.1.26040.8 vulnerable

Related weakness (CWE)

CWE-59

Remediation plan

1

Apply official patches

Microsoft has released updates for the Malware Protection Engine to address this link resolution flaw. Ensure the engine is updated automatically via Windows Update or manually through Microsoft Endpoint Configuration Manager.

2

Update affected systems

Verify that the Microsoft Malware Protection Engine is updated to version 1.1.26040.8 or later. Systems running versions starting from 1.1.26030.3008 up to 1.1.26040.7 are confirmed vulnerable and require immediate remediation.

3

Restrict access

Since this is a local privilege escalation (LPE) vulnerability, enforce the principle of least privilege (PoLP) and restrict local interactive login access to sensitive servers to minimize the number of users capable of executing local exploits.

4

Monitor for exploitation

Utilize EDR and SIEM tools to monitor for suspicious symbolic link or hard link creation in system directories, particularly those associated with Microsoft Defender's temporary file locations or update folders.

Detection Guidance

Detection should focus on identifying unusual file system operations. Monitor Windows Event ID 4663 for attempts to access objects involving symbolic links or junctions created by low-privileged users in system-protected paths. Specifically, look for processes attempting to redirect Defender’s file operations to sensitive system files. Host-based behavioral analysis of symlink creation and 'link following' behavior is the most effective way to identify potential exploitation attempts in real-time.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management