Description
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Published: 2026-04-14
Score: 7.8 High
EPSS: 5.6% Low
KEV: Yes
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 23:30:00 +0000


Wed, 22 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-04-22T00:00:00+00:00', 'dueDate': '2026-05-06T00:00:00+00:00'}


Wed, 22 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
References

Mon, 20 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft defender Antimalware Platform
CPEs cpe:2.3:a:microsoft:defender_antimalware_platform:*:*:*:*:*:*:*:*
Vendors & Products Microsoft defender Antimalware Platform

Wed, 15 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Defender Antimalware Platform
Vendors & Products Microsoft windows Defender Antimalware Platform

Wed, 15 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 17:30:00 +0000

Type Values Removed Values Added
Description Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Title Microsoft Defender Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft microsoft Defender
Weaknesses CWE-1220
CPEs cpe:2.3:a:microsoft:microsoft_defender:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft microsoft Defender
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Microsoft Defender Antimalware Platform Microsoft Defender Windows Defender Antimalware Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-05-12T17:38:43.822Z

Reserved: 2026-03-24T00:52:01.352Z

Link: CVE-2026-33825

cve-icon Vulnrichment

Updated: 2026-04-15T09:08:59.756Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-14T18:17:35.100

Modified: 2026-04-23T17:26:30.713

Link: CVE-2026-33825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T16:30:35Z

Weaknesses