cbcvebase.
CVE-2026-41091
published 2026-05-20

CVE-2026-41091: Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEV
CISA Known Exploited Vulnerabilitydue 2026-06-03
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Affected

2 ranges
VendorProductVersion rangeFixed in
microsoftmalware_protection_engine>= 1.1.26030.3008 < 1.1.26040.81.1.26040.8
microsoftmicrosoft_malware_protection_engine>= 1.1.0.0 < 1.1.26040.81.1.26040.8

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH