Junglewise Threat Intelligence

CVE-2026-45647: Microsoft Defender for Endpoint privilege escalation via TOCTOU race condition

CVE-2026-45647 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A security vulnerability exists in Microsoft Defender for Endpoint, the primary security software used to protect corporate computers from malware and cyberattacks. An attacker who already has basic access to a computer could exploit a timing flaw to gain higher-level administrative permissions. This could allow them to bypass security controls or modify system files that should normally be protected.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists within Microsoft Defender for Endpoint, classified as CWE-367. The vulnerability occurs when the application checks a resource (such as a file or configuration) but the state of that resource changes before it is actually used by the service. An attacker with local access and low-level privileges can exploit this window of opportunity to manipulate system processes. Successful exploitation allows the attacker to elevate their privileges to a higher level, potentially gaining unauthorized integrity over system components. The attack requires local authentication but no user interaction.

Affected products

  • Microsoft Defender for Endpoint

Timeline

  • 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.

References

Related threats