Microsoft released out-of-band patches for two zero-day vulnerabilities in the Windows Defender Antimalware Platform on May 21, 2026. Real-world attacks had already exploited these flaws before Microsoft issued fixes. The vulnerabilities carry the public names RedSun and UnDefend.
Microsoft releases out-of-band patches for two exploited Windows Defender vulnerabilities
The first flaw, CVE-2026-41091, carries a CVSS score of 7.8. It stems from improper link resolution in the Malware Protection Engine. Attackers can manipulate symbolic links or directory junctions during scans to escalate privileges to full SYSTEM-level control without elevated starting permissions.
The second flaw, CVE-2026-45498, holds a CVSS score of 4.0. It functions as a denial-of-service attack that silently blocks definition updates across multiple Defender platforms. The issue affects System Center Endpoint Protection, Security Essentials, and standard Windows Defender installations.
Microsoft resolved both vulnerabilities in Malware Protection Engine version 1.1.26040.8 and Antimalware Platform version 4.18.26040.7. The company delivers the updates automatically through the built-in update mechanism. Administrators should verify their deployments run these versions or newer.
CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on May 20, 2026. Federal Civilian Executive Branch agencies must confirm patching by June 3. The same engine update also addresses CVE-2026-45584, which remains unconfirmed in active exploitation.
Source: NotebookCheck




Discussion
0 comments