Executive brief
A security vulnerability exists in Microsoft Defender, the built-in antivirus and security software for Windows. An attacker could exploit this flaw to run unauthorized code on a target system, potentially leading to a full system takeover. While the attack requires a user to perform an action, such as opening a malicious file, it poses a significant risk to data confidentiality and system integrity.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in the Microsoft Malware Protection Engine, which can lead to a heap-based buffer overflow (CWE-122). The vulnerability is triggered when the engine parses a specially crafted file. An attacker who successfully exploits this could execute arbitrary code in the security context of the LocalSystem account. The attack vector is local, requiring a user to open or interact with a malicious file (User Interaction: Required). The issue affects versions 1.1.0.0 through 1.1.26060.3008 and is addressed in subsequent updates.
Affected products
- Microsoft Malware Protection Engine 1.1.0.0 to 1.1.26060.3008
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD.