Executive brief
Microsoft Defender, the built-in security and antivirus suite for Windows, contains a vulnerability that could allow a user with limited access to gain full administrative control over a system. By exploiting how the software handles file shortcuts, an attacker can trick the system into modifying or accessing protected files. This flaw has been reported as being actively exploited in the wild, posing a significant risk to system integrity and data confidentiality.
Technical details
A link following vulnerability (CWE-59) exists in Microsoft Defender due to improper link resolution before file access. A local attacker with low privileges can exploit this by creating symbolic links or junctions that point to sensitive system files, which the Defender service may then interact with at a higher privilege level. Successful exploitation allows the attacker to achieve full SYSTEM-level privileges, leading to complete compromise of the affected host. This vulnerability is reportedly being exploited in the wild and requires a local presence on the target machine.
Affected products
- Microsoft Defender
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory
- 2026-05-20: exploited: Reported as exploited in the wild at time of disclosure.