cbcvebase.
CVE-2026-45498
published 2026-05-20

CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability

PriorityP276high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-06-03
Exploited in the wild
EPSS
63.08%
99.1th percentile
Microsoft Defender Denial of Service Vulnerability

Affected

2 ranges
VendorProductVersion rangeFixed in
microsoftdefender_antimalware_platform< 4.18.26040.74.18.26040.7
microsoftmicrosoft_defender_antimalware_platform>= 4.0.0.0 < 4.18.26040.74.18.26040.7

Detection & IOCsextracted from sources · hover to see the quote

versionMicrosoft Malware Protection Engine 1.1.26060.3008
  • CVE-2026-45498 has been confirmed exploited in the wild; treat any unexpected Defender definition update failures on standard-user sessions as a potential exploitation indicator.
  • CVE-2026-45498 is a Denial of Service flaw against the Malware Protection Engine (mpengine.dll); alert on unexpected termination or non-responsiveness of mpengine.dll processes.
  • Exploit code for CVE-2026-45498 was publicly released by researcher Chaotic Eclipse (aka Nightmare-Eclipse / MSNightmare) via GitHub and GitLab before account takedowns; hunt for PoC artifacts in the environment.
  • ·Defender definition updates are delivered automatically; enterprise deployments should verify the update channel is functioning and not silently blocked, as CVE-2026-45498 specifically targets this mechanism.
  • ·No customer action is required to receive the Defender engine update; however, enterprise environments with manually managed or air-gapped update configurations may not receive the fix automatically and require manual intervention.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vulncheck7.5HIGH
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.