Microsoft Defender For Endpoint vulnerabilities
6 known vulnerabilities affecting microsoft/defender_for_endpoint.
Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-59497MEDIUMCVSS 4.7fixed in 101.25032.00102025-10-14
CVE-2025-59497 [MEDIUM] CWE-367 CVE-2025-59497: Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authoriz
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.
nvd
CVE-2025-47161HIGHCVSS 7.8PoCfixed in 101.25022.00022025-05-15
CVE-2025-47161 [HIGH] CWE-284 CVE-2025-47161: Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26684MEDIUMCVSS 6.7fixed in 101.25032.00082025-05-13
CVE-2025-26684 [MEDIUM] CWE-73 CVE-2025-26684: External control of file name or path in Microsoft Defender for Endpoint allows an authorized attack
External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49057HIGHCVSS 8.1fixed in 1.0.7128.01012024-12-12
CVE-2024-49057 [HIGH] CWE-20 CVE-2024-49057: Microsoft Defender for Endpoint on Android Spoofing Vulnerability
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
nvd
CVE-2024-43614MEDIUMCVSS 5.5fixed in 101.24052.00022024-10-08
CVE-2024-43614 [MEDIUM] CWE-23 CVE-2024-43614: Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
nvd
CVE-2024-21315HIGHCVSS 7.8fixed in 10.0.25398.531fixed in 10.0.19045.3693+10 more2024-02-13
CVE-2024-21315 [HIGH] CWE-20 CVE-2024-21315: Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
nvd