Executive brief
A security vulnerability exists in Microsoft Defender for Endpoint, the primary security software used to protect corporate computers from malware and cyberattacks. An attacker who already has basic access to a computer could exploit a timing flaw to gain higher-level administrative permissions. This could allow them to bypass security controls or modify system files that should normally be protected.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) race condition exists within Microsoft Defender for Endpoint, classified as CWE-367. The vulnerability occurs when the application checks a resource (such as a file or configuration) but the state of that resource changes before it is actually used by the service. An attacker with local access and low-level privileges can exploit this window of opportunity to manipulate system processes. Successful exploitation allows the attacker to elevate their privileges to a higher level, potentially gaining unauthorized integrity over system components. The attack requires local authentication but no user interaction.
Affected products
- Microsoft Defender for Endpoint
Timeline
- 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.