cbcvebase.
CVE-2026-41091
published 2026-05-20

CVE-2026-41091: Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

PriorityP184high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-06-03
Exploited in the wild
EPSS
8.37%
94.3th percentile
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Affected

2 ranges
VendorProductVersion rangeFixed in
microsoftmalware_protection_engine>= 1.1.26030.3008 < 1.1.26040.81.1.26040.8
microsoftmicrosoft_malware_protection_engine>= 1.1.0.0 < 1.1.26040.81.1.26040.8

Detection & IOCsextracted from sources · hover to see the quote

filenamempengine.dll
versionMicrosoft Malware Protection Engine 1.1.26060.3008
  • CVE-2026-41091 (RedSun) is a local privilege escalation flaw in Microsoft Defender exploited in the wild; monitor for unexpected SYSTEM-level process spawning from Defender-related processes.
  • The exploit technique involves a race condition (link following / path redirection) in the Microsoft Malware Protection Engine; monitor for symlink or junction creation activity targeting Defender file paths.
  • The RoguePlanet PoC (related researcher, same Defender engine) works regardless of whether real-time protection is enabled or in passive mode; do not rely on Defender real-time protection status as an indicator of exploitation.
  • On Windows desktop (not Server), the exploit chain for the related Defender race-condition flaw uses ISO image mounting as a primitive; monitor for standard users mounting ISO images in conjunction with Defender process activity.
  • Exploit code for CVE-2026-41091 (RedSun) was published by researcher 'MSNightmare' on GitHub/GitLab before account takedowns; monitor for re-uploads or forks of this PoC code in threat actor repositories.
  • ·CVE-2026-41091 (RedSun) has been patched by Microsoft; Defender updates are delivered automatically, but enterprise environments with manual update configurations may remain exposed until definitions and engine are explicitly updated.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.