Skip to content
Actively exploitedCVSS 7.8 · HIGH

CVE-2026-33825Privilege Escalation in Microsoft Defender

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

View on NVD

Analysis

Esta vulnerabilidad en Microsoft Defender permite a un atacante con acceso local elevar sus privilegios para tomar control total del sistema. El fallo está siendo explotado activamente según el reporte de CISA, lo que pone en riesgo estaciones de trabajo y servidores Windows. Es necesario asegurar que las actualizaciones automáticas del motor antimalware estén aplicadas.

Severity

Score: 7.8(HIGH)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: LOCAL
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-1220

CISA KEV

Added to KEV: 2026-04-22
Federal patch deadline: 2026-05-06
Known ransomware use: Unknown
Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probability of exploitation (next 30 days): 0.0675 (6.7%)
Percentile: 93.3%
EPSS: 2026-07-24

Affects

microsoft:defender_antimalware_platform

Technical description

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Published: 4/14/2026, 6:17:35 PM
Last modified: 7/24/2026, 10:10:00 PM

References

HomeEventsBlogResourcesCoursesTeam