CVE-2026-33825Privilege Escalation in Microsoft Defender
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
View on NVDAnalysis
Esta vulnerabilidad en Microsoft Defender permite a un atacante con acceso local elevar sus privilegios para tomar control total del sistema. El fallo está siendo explotado activamente según el reporte de CISA, lo que pone en riesgo estaciones de trabajo y servidores Windows. Es necesario asegurar que las actualizaciones automáticas del motor antimalware estén aplicadas.
Severity
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCWE-1220CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
EPSS
Affects
microsoft:defender_antimalware_platformTechnical description
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.