CVE-2026-33825highunder attackransomwareCWE-1220

CVE-2026-33825: high-severity vulnerability in Microsoft Defender Antimalware Platform

Microsoft Defender Elevation of Privilege Vulnerability

Published · Updated

71Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 0.4%
from disclosure to weapon18 days
Published on NVDApr 14
1st PoC+18d
CISA KEV+8d
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2026-05-06

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Microsoft Defender has a flaw in its access controls that lets someone who already has limited access on your computer gain higher-level privileges without authorization. This is dangerous because it allows an attacker to take full control of the system.

Technical detail

An insufficient granularity of access control mechanism in Microsoft Defender permits an authorized local user to escalate privileges through CWE-1220 (Inappropriate Granularity). The vulnerability requires prior local access and valid credentials but allows complete privilege elevation, impacting system confidentiality, integrity, and availability.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Microsoft Defender Antimalware Platform

In the same product, most dangerous first.