PHONES Apple Upgrade Leasing Program Launches July 28 for iPhones and Macs ANDROID Oppo Pad 5 Pro Battery Life Doubles iPad Pro 13 Runtime GAMES Unity Underground: Full Ultima Underworld Remake Now Available GAMES Wreckreation 2 Announced: Tides Turn’s Burnout-Style Arcade Racer PHONES Light Flip Launches as $299 5G Flip Phone With OLED and Minimalist OS GAMES EA Sports FC 27 Gameplay Reveal Premiere: Date, Time & How To Watch GAMES Dear Passengers Price Guide Released by Insider Gaming PC HARDWARE Vivo, Oppo Reject Samsung DRAM Price Hike as Supply Crunch Tightens NINTENDO SWITCH Unpetrified: Echoes of Nature Console Release Confirmed for Fall 2026 PHONES Huawei Leads China Smartphone Market as Apple Grows Amid 2% Decline GAMES Phasmophobia Gets Deildegast Ghost and 13 Willow Street Rework STEAM Fallout 76 Update 2.28 Released: Infestations Rebalanced and Boss Loot Fixed GAMES Former Forza Director Calls Xbox Game Pass ‘A Real Shame’ GAMES Bethesda Takes Fallout 76 Servers Offline for July 21 Title Update

Microsoft Patches Defender Zero-Days RedSun and UnDefend

Simon Ellis 0 comments 1 min read

Microsoft released out-of-band patches for two exploited zero-day vulnerabilities in the Windows Defender Antimalware Platform, CVE-2026-41091 and CVE-2026-45498.

Microsoft Patches Defender Zero-Days RedSun and UnDefend
SOFTWARE AND UPDATES

Microsoft released out-of-band patches for two zero-day vulnerabilities in the Windows Defender Antimalware Platform on May 21, 2026. Real-world attacks had already exploited these flaws before Microsoft issued fixes. The vulnerabilities carry the public names RedSun and UnDefend.

Microsoft releases out-of-band patches for two exploited Windows Defender vulnerabilities

The first flaw, CVE-2026-41091, carries a CVSS score of 7.8. It stems from improper link resolution in the Malware Protection Engine. Attackers can manipulate symbolic links or directory junctions during scans to escalate privileges to full SYSTEM-level control without elevated starting permissions.

The second flaw, CVE-2026-45498, holds a CVSS score of 4.0. It functions as a denial-of-service attack that silently blocks definition updates across multiple Defender platforms. The issue affects System Center Endpoint Protection, Security Essentials, and standard Windows Defender installations.

Microsoft resolved both vulnerabilities in Malware Protection Engine version 1.1.26040.8 and Antimalware Platform version 4.18.26040.7. The company delivers the updates automatically through the built-in update mechanism. Administrators should verify their deployments run these versions or newer.

CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on May 20, 2026. Federal Civilian Executive Branch agencies must confirm patching by June 3. The same engine update also addresses CVE-2026-45584, which remains unconfirmed in active exploitation.

Source: NotebookCheck

Discussion

0 comments

Leave a comment