FSR Onimusha: Way of the Sword Steam Deck Performance Guide NINTENDO SWITCH 2 Digimon Story: Time Stranger DLC ‘A Hero’s Eternal Legacy’ Announced PLAYSTATION 5 Cygames Launches Where the Seeds Fall for PS5, Switch 2, and PC PLAYSTATION 5 Dragon Ball Xenoverse 3 Trailer Reveals New Android Avatar Race PLAYSTATION 5 Uncanyon Puzzle Adventure Announced for PS5, Xbox Series, Switch 2, and PC NINTENDO Final Fantasy Resonance Demo Now Live With Save Carryover HANDHELD GAMING FunnyPlaying Retro Pixel MiniGB Brings Game Boy Cartridges to a 2.6-Inch Handheld CONSOLES LEGO PlayStation Set Ships October 4 for $180 With Opening Disc Drive NINTENDO SWITCH How To Fish Console Availability: PS5, Xbox Series X|S, and Switch DLSS NVIDIA DLSS Multi Frame Generation Mod Brings Blackwell Tech to RTX 40 Series GAMES Killing Floor 3 Update 2.017 Fixes Stuttering and Buffs Damage PC HARDWARE Acer EP130K ePaper Monitor: 13.3-inch 3.2K Display Ships in 2027 AYANEO MSI Claw 8 EX AI+ Gets $1,499 Price Cut With Arc B370 GPU GAMES GTA 6 Miami Marketing Blocked by Sheriff Over Crime Stereotypes

Microsoft Patches Defender Zero-Days RedSun and UnDefend

Simon Ellis 1 min read

Microsoft released out-of-band patches for two exploited zero-day vulnerabilities in the Windows Defender Antimalware Platform, CVE-2026-41091 and CVE-2026-45498.

Microsoft Patches Defender Zero-Days RedSun and UnDefend
SOFTWARE AND UPDATES

Microsoft released out-of-band patches for two zero-day vulnerabilities in the Windows Defender Antimalware Platform on May 21, 2026. Real-world attacks had already exploited these flaws before Microsoft issued fixes. The vulnerabilities carry the public names RedSun and UnDefend.

Microsoft releases out-of-band patches for two exploited Windows Defender vulnerabilities

The first flaw, CVE-2026-41091, carries a CVSS score of 7.8. It stems from improper link resolution in the Malware Protection Engine. Attackers can manipulate symbolic links or directory junctions during scans to escalate privileges to full SYSTEM-level control without elevated starting permissions.

The second flaw, CVE-2026-45498, holds a CVSS score of 4.0. It functions as a denial-of-service attack that silently blocks definition updates across multiple Defender platforms. The issue affects System Center Endpoint Protection, Security Essentials, and standard Windows Defender installations.

Microsoft resolved both vulnerabilities in Malware Protection Engine version 1.1.26040.8 and Antimalware Platform version 4.18.26040.7. The company delivers the updates automatically through the built-in update mechanism. Administrators should verify their deployments run these versions or newer.

CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on May 20, 2026. Federal Civilian Executive Branch agencies must confirm patching by June 3. The same engine update also addresses CVE-2026-45584, which remains unconfirmed in active exploitation.

Source: NotebookCheck