Junglewise Threat Intelligence

CVE-2026-50658: Microsoft Defender for Endpoint for Mac privilege escalation via TOCTOU

CVE-2026-50658 · Severity: high · CVSS 7 · Published 2026-07-14

Vendors: Microsoft.

Executive brief

Microsoft Defender for Endpoint, a security tool used to protect enterprise computers from malware and cyber threats, contains a vulnerability that could allow a user with limited access to gain higher-level administrative permissions. By exploiting a timing flaw during file checks, an attacker who already has a foothold on a Mac system could bypass security restrictions to gain full control over the device. This could lead to the theft of sensitive data or the disabling of security protections.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists in Microsoft Defender for Endpoint for Mac (versions 101.0.0 through 101.26042.0020). The vulnerability, classified as CWE-367, occurs when the application checks a file property or state but the state changes before the file is actually used. An attacker with local user access (PR:L) can exploit this high-complexity (AC:H) race condition to execute code with elevated privileges. Successful exploitation grants the attacker full confidentiality, integrity, and availability impact on the affected system. Microsoft has addressed this issue in updated versions of the Defender client.

Affected products

  • Microsoft Microsoft Defender for Endpoint for Mac 101.0.0 to 101.26042.0020

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats