« Back to list

Microsoft

Microsoft Defender Antimalware Platform: vulnerabilities and CVEs

Microsoft Defender Antimalware Platform has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 2 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-45498High (7.5)1.3%⚠ Active exploitationMay 20, 2026
Microsoft Defender Denial of Service Vulnerability
CVE-2026-33825High (7.8)0.40%⚠ Active exploitationApr 14, 2026
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-45498High (7.5)1.3%⚠ Active exploitationMay 20, 2026
Microsoft Defender Denial of Service Vulnerability
CVE-2026-33825High (7.8)0.40%⚠ Active exploitationApr 14, 2026
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation1
  2. T1190 Exploit Public-Facing Application1
  3. T1499.004 Application or System Exploitation1
  4. T1548 Abuse Elevation Control Mechanism1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft