CVE-2026-41091
Microsoft Microsoft Malware Protection Engine, malware protection engine
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
- CVSS
- 7.8
- EPSS
- 9.64% 95.0% percentile
- CISA KEV
- Listed
- Published
- 2026.05.20