Executive brief
Microsoft Defender, the built-in antivirus and security suite for Windows, is susceptible to a denial of service vulnerability. An attacker could exploit this flaw to disable or crash the security software, potentially leaving the system unprotected against other threats. While the vulnerability is reported as being exploited in the wild, it requires local access to the target machine to execute.
Technical details
Microsoft Defender is vulnerable to a denial of service (DoS) attack due to an unspecified flaw. The vulnerability is triggered via a local attack vector (AV:L) with low complexity and requires no special privileges or user interaction. Successful exploitation allows an attacker to impact the availability of the Defender service, potentially disabling real-time protection or scanning capabilities. Although the advisory mentions the flaw has been exploited in the wild, the CVSS score provided by Microsoft is 4.0 (Medium). Users should refer to the Microsoft Security Response Center (MSRC) for specific patch details and version information.
Affected products
- Microsoft Defender
Timeline
- 2026-05-20: disclosed
- 2026-05-20: advisory
- 2026-05-20: exploited: Reported as exploited in the wild in the advisory summary.