Junglewise Threat Intelligence

CVE-2026-45584: Microsoft Defender heap buffer overflow

CVE-2026-45584 · Severity: high · CVSS 8.1 · Published 2026-05-20

Technologies: Microsoft Defender. Vendors: Microsoft.

Executive brief

Microsoft Defender, the built-in security and antivirus software for Windows, contains a critical vulnerability that could allow a remote attacker to take control of a system. By exploiting a memory handling error, an unauthorized user could execute malicious code over the network. This poses a significant risk to data confidentiality and system availability, potentially allowing for full system compromise without any user interaction.

Technical details

A heap-based buffer overflow (CWE-122) exists in Microsoft Defender. The vulnerability is reachable over the network and does not require user interaction or administrative privileges (PR:N/UI:N). However, the attack complexity is rated as high (AC:H), suggesting specific timing or environmental conditions are required for successful exploitation. If successfully exploited, an attacker can achieve remote code execution (RCE) with the privileges of the Defender service, leading to a total loss of confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Defender

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory

References

Related threats