Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-45498

Published 2026-05-20
Updated 2 months ago
Vendor/s
Microsoft
Product/s
Defender
Version/s
* > 4.18.26040.7
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
4
/ 10
Medium
Severity Details
Base score
4 Medium
Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Description

CVE-2026-45498 is a Medium-severity DoS vulnerability in Microsoft Defender actively exploited in the wild. Update to version 4.18.26040.7 immediately.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
defender_antimalware_platform * 4.18.26040.7 vulnerable

Related weakness (CWE)

CWE-400

Remediation plan

1

Apply official patches

Microsoft has released specific security updates to address this vulnerability within the Defender Antimalware Platform. Administrators should use Windows Update, WSUS, or Microsoft Endpoint Configuration Manager to deploy the latest security intelligence and engine updates.

2

Update affected systems

Verify that all Windows endpoints and servers are running Microsoft Defender Antimalware Platform version 4.18.26040.7 or higher. Systems running versions prior to this are considered vulnerable and must be updated immediately.

3

Restrict access

Given the local attack vector, enforce the principle of least privilege (PoLP) by restricting local administrative privileges and limiting interactive logon rights to minimize the surface area for potential exploitation by unauthorized local users.

4

Monitor for exploitation

Implement automated monitoring for frequent crashes or restarts of the 'MsMpEng.exe' process. Track Windows System Event IDs 7031 and 7034, which indicate the Microsoft Defender Antimalware Service has terminated unexpectedly.

Detection Guidance

"Detection should focus on identifying service instability within Microsoft Defender. Monitor Windows Event Logs for Event IDs 7031, 7034, or 7036, which indicate the Microsoft Defender Antimalware Service has stopped or restarted unexpectedly. Additionally, use performance monitoring tools to alert on abnormal CPU or memory spikes originating from the Defender process (MsMpEng.exe), which may suggest an attempt to trigger a Denial of Service condition through resource exhaustion."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management