CVE-2026-33825: high-severity vulnerability in Microsoft Defender Antimalware Platform
Microsoft Defender Elevation of Privilege Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Microsoft Defender has a flaw in its access controls that lets someone who already has limited access on your computer gain higher-level privileges without authorization. This is dangerous because it allows an attacker to take full control of the system.
An insufficient granularity of access control mechanism in Microsoft Defender permits an authorized local user to escalate privileges through CWE-1220 (Inappropriate Granularity). The vulnerability requires prior local access and valid credentials but allows complete privilege elevation, impacting system confidentiality, integrity, and availability.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.