Junglewise Threat Intelligence

CVE-2026-56178: Microsoft Defender for Endpoint TOCTOU privilege escalation

CVE-2026-56178 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Vendors: Microsoft.

Executive brief

Microsoft Defender for Endpoint is a security platform designed to help enterprise networks prevent, detect, and respond to advanced threats. A vulnerability in the Mac version of this software could allow a user who already has basic access to a computer to gain higher-level system permissions. This could allow an attacker to bypass security restrictions or interfere with the system's integrity.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists in Microsoft Defender for Endpoint for Mac (versions prior to 101.26042.0020). The vulnerability, classified as CWE-367, occurs when the application checks a resource property before using that resource, but the property changes between the check and the use. An attacker with local access and low-level privileges can exploit this timing window to perform unauthorized actions with elevated permissions. The attack requires local authentication but no user interaction. Microsoft has addressed this in updated versions of the Defender for Endpoint client.

Affected products

  • Microsoft Microsoft Defender for Endpoint for Mac 101.0.0 to 101.26042.0020

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats