HIGH

CVE-2026-41091

Microsoft Malware Protection Engine 2026-05-20 CVSS v3.1
CVSS
7.8
KEV

Description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Summary dbcve.org

A link following vulnerability (CWE-59) in Microsoft Defender allows an authorized local attacker to manipulate symbolic links during file access operations, potentially escalating privileges by causing Defender to access or modify files it should not have access to.

Mitigation

Apply Microsoft's security updates for Defender when available; in the interim, restrict write access to Defender's directories and monitor for unauthorized symlink creation in protected paths.

Weakness (CWE)

CWE-59 Link Following (Symlink)

EPSS Score

8.2%
Probability of exploitation in next 30 days
94.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE