Executive brief
A security vulnerability exists in Microsoft Defender, the built-in antivirus and security software for Windows. An attacker who already has limited access to a computer could exploit this flaw to run malicious code with elevated permissions. This could lead to a full system takeover, allowing the attacker to steal data, install ransomware, or disrupt business operations.
Technical details
An integer underflow (CWE-191) exists in the Microsoft Malware Protection Engine (Microsoft Defender). The vulnerability is triggered when the engine processes specially crafted files, leading to a memory corruption condition. While the attack vector is classified as local, it requires user interaction (UI:R), such as a user downloading or opening a malicious file that Defender then scans. Successful exploitation allows an unauthorized attacker to execute arbitrary code in the security context of the LocalSystem account, effectively gaining full control over the host. Microsoft has released updates to address this issue in version 1.1.26060.3008 and later.
Affected products
- Microsoft Malware Protection Engine 1.1.0.0 to 1.1.26060.3008
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory