CVE-2026-45498 is a Medium-severity DoS vulnerability in Microsoft Defender actively exploited in the wild. Update to version 4.18.26040.7 immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| defender_antimalware_platform | * | 4.18.26040.7 | vulnerable |
Microsoft has released specific security updates to address this vulnerability within the Defender Antimalware Platform. Administrators should use Windows Update, WSUS, or Microsoft Endpoint Configuration Manager to deploy the latest security intelligence and engine updates.
Verify that all Windows endpoints and servers are running Microsoft Defender Antimalware Platform version 4.18.26040.7 or higher. Systems running versions prior to this are considered vulnerable and must be updated immediately.
Given the local attack vector, enforce the principle of least privilege (PoLP) by restricting local administrative privileges and limiting interactive logon rights to minimize the surface area for potential exploitation by unauthorized local users.
Implement automated monitoring for frequent crashes or restarts of the 'MsMpEng.exe' process. Track Windows System Event IDs 7031 and 7034, which indicate the Microsoft Defender Antimalware Service has terminated unexpectedly.
"Detection should focus on identifying service instability within Microsoft Defender. Monitor Windows Event Logs for Event IDs 7031, 7034, or 7036, which indicate the Microsoft Defender Antimalware Service has stopped or restarted unexpectedly. Additionally, use performance monitoring tools to alert on abnormal CPU or memory spikes originating from the Defender process (MsMpEng.exe), which may suggest an attempt to trigger a Denial of Service condition through resource exhaustion."
Experience superior visibility and a simpler approach to cyber risk management