CVE-2026-45584 – Microsoft Defender

CVSS 8.1 IMPORTANT

“A security engine under attack becomes a business risk the moment it falls behind on patches.”

Microsoft released patches for three vulnerabilities impacting the Microsoft Defender Antimalware Platform and Microsoft Malware Protection Engine. Two of the vulnerabilities are confirmed as actively exploited. CVE-2026-45498 has a CVSS score of 4.0, which is Medium severity. CVE-2026-41091 and CVE-2026-33825 have a CVSS score of 7.8, which is High severity. CVE-2026-45584 has a CVSS score of 8.1, which is High severity.

The update addresses a denial-of-service issue, a local elevation-of-privilege vulnerability, and a heap-based memory issue that could allow remote code execution. The elevation-of-privilege vulnerability can allow attackers to gain higher local access, while the remote code execution issue affects the Malware Protection Engine responsible for scanning and processing content.

Key Details

Affected Product
Microsoft Malware Protection Engine
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.