HIGH
CVE-2026-41091
CVSS
7.8
KEV
Description
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
A link following vulnerability (CWE-59) in Microsoft Defender allows an authorized local attacker to manipulate symbolic links during file access operations, potentially escalating privileges by causing Defender to access or modify files it should not have access to.
Mitigation
Apply Microsoft's security updates for Defender when available; in the interim, restrict write access to Defender's directories and monitor for unauthorized symlink creation in protected paths.
Weakness (CWE)
CWE-59
Link Following (Symlink)
EPSS Score
8.2%
Probability of exploitation in next 30 days
94.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.