Microsoft
Microsoft Defender Antimalware Platform: vulnerabilities and CVEs
Microsoft Defender Antimalware Platform has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 2 are listed by CISA as actively exploited.
CVEs2
Last 12 months2
Critical0
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45498 | High (7.5) | 1.3% | ⚠ Active exploitation | May 20, 2026 | Microsoft Defender Denial of Service Vulnerability |
| CVE-2026-33825 | High (7.8) | 0.40% | ⚠ Active exploitation | Apr 14, 2026 | Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45498 | High (7.5) | 1.3% | ⚠ Active exploitation | May 20, 2026 | Microsoft Defender Denial of Service Vulnerability |
| CVE-2026-33825 | High (7.8) | 0.40% | ⚠ Active exploitation | Apr 14, 2026 | Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.