CVE-2026-41091 is a local privilege escalation vulnerability in Microsoft Malware Protection Engine affecting Windows Defender. The vulnerability requires local access and existing low-level privileges to exploit, making it unsuitable for direct internet exploitation despite being in CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: OTHER
CVE Published: 2026-05-20
Added to CISA KEV: 2026-05-20 0 DAY BETWEEN CVE AND KEV
CVE-2026-41091 is a critical security vulnerability affecting the Microsoft Malware Protection Engine, which is the core component of Microsoft Defender. Below is a summary of the known details regarding this vulnerability.
The first one, tracked as CVE-2026-41091, is a privilege escalation security flaw affecting Microsoft Malware Protection Engine 1.1.26030.3008 ... On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. The first oneβ¦
CVE-2026-41091 allows for local privilege elevation (LPE), and is caused by the Microsoft Malware Protection Engine improperly resolving links ...
It allows a low-privileged authenticated attacker to achieve SYSTEM privileges by tricking Defender's remediation and cloud file rollback ...
Microsoft this week released patches for two vulnerabilities in Defender, warning they have been exploited in the wild as zero-days. The first, tracked as CVE-2026-41091 (CVSS score of 7.8), is described as a link-following issue that allows attackers to elevate their privileges to System.