Microsoft Defender For Endpoint vulnerabilities

6 known vulnerabilities affecting microsoft/defender_for_endpoint.

Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-59497MEDIUMCVSS 4.7fixed in 101.25032.00102025-10-14
CVE-2025-59497 [MEDIUM] CWE-367 CVE-2025-59497: Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authoriz Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.
nvd
CVE-2025-47161HIGHCVSS 7.8PoCfixed in 101.25022.00022025-05-15
CVE-2025-47161 [HIGH] CWE-284 CVE-2025-47161: Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-26684MEDIUMCVSS 6.7fixed in 101.25032.00082025-05-13
CVE-2025-26684 [MEDIUM] CWE-73 CVE-2025-26684: External control of file name or path in Microsoft Defender for Endpoint allows an authorized attack External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-49057HIGHCVSS 8.1fixed in 1.0.7128.01012024-12-12
CVE-2024-49057 [HIGH] CWE-20 CVE-2024-49057: Microsoft Defender for Endpoint on Android Spoofing Vulnerability Microsoft Defender for Endpoint on Android Spoofing Vulnerability
nvd
CVE-2024-43614MEDIUMCVSS 5.5fixed in 101.24052.00022024-10-08
CVE-2024-43614 [MEDIUM] CWE-23 CVE-2024-43614: Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
nvd
CVE-2024-21315HIGHCVSS 7.8fixed in 10.0.25398.531fixed in 10.0.19045.3693+10 more2024-02-13
CVE-2024-21315 [HIGH] CWE-20 CVE-2024-21315: Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
nvd