Skip to content
Activamente explotadaCVSS 7.8 · HIGH

CVE-2026-33825Escalada de privilegios en Microsoft Defender

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

Ver en NVD

Análisis

Esta vulnerabilidad en Microsoft Defender permite a un atacante con acceso local elevar sus privilegios para tomar control total del sistema. El fallo está siendo explotado activamente según el reporte de CISA, lo que pone en riesgo estaciones de trabajo y servidores Windows. Es necesario asegurar que las actualizaciones automáticas del motor antimalware estén aplicadas.

Severidad

Puntaje: 7.8(HIGH)
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: LOCAL
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-1220

CISA KEV

Agregada al KEV: 2026-04-22
Fecha límite federal: 2026-05-06
Uso conocido en ransomware: Unknown
Acción requerida

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probabilidad de explotación (próx. 30 días): 0.0675 (6.7%)
Percentil: 93.3%
EPSS: 2026-07-24

Afecta

microsoft:defender_antimalware_platform

Descripción técnica

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Publicada: 14/4/2026, 18:17:35
Última modificación: 24/7/2026, 22:10:00

Referencias

InicioEventosBlogRecursosCursosEquipo