Junglewise Threat Intelligence

CVE-2026-69414: Microsoft Defender Malware Protection Engine elevation of privilege

CVE-2026-69414 · Severity: high · CVSS 7.8 · Published 2026-08-14

Technologies: Microsoft Malware Protection Engine, Microsoft Defender. Vendors: Microsoft.

Executive brief

Microsoft Defender's Malware Protection Engine contains an elevation of privilege vulnerability known as "ShieldBreak." This engine is a core component of Microsoft Defender antivirus that scans files and processes to detect and remove malware. An attacker could exploit this flaw to gain higher system privileges, potentially bypassing security controls and taking complete control of an affected computer.

Technical details

This vulnerability is an elevation of privilege (EoP) flaw in the Microsoft Malware Protection Engine, a critical component of Microsoft Defender antivirus. The specific root cause and attack vector are not publicly disclosed in the available advisory material. However, based on the reported CVSS score of 7.8 and classification as elevation of privilege, the flaw likely allows local or adjacent attackers to gain SYSTEM-level privileges on an affected system. The vulnerability has not been reported as actively exploited in the wild as of the publication date. Microsoft has issued a security update to address this issue.

Affected products

  • Microsoft Defender

Timeline

  • 2026-08-14: disclosed

References

Related threats