← Back to browse · API

CVE-2026-41091

Severity
HIGH
CVSS
7.8
EPSS
0.09641
Risk score
59.57
CISA KEV
Yes
PoC
Yes
Published
2026-05-20
Modified
2026-06-19
First seen
2026-08-05
Aliases
EUVD-2026-31101, GHSA-H776-J9JW-992P
Products
Microsoft:Defender, Microsoft:Microsoft Malware Protection Engine 1.1.0.0 <1.1.26040.8, microsoft:malware_protection_engine
Sources
nvd CVE-2026-41091
cisa.gov CVE-2026-41091
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-41091
euvd EUVD-2026-31101
packetstorm 83fc4cd6348bb75e37997fe0|CVE-2026-41091

Description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

References