CyberICT

CVE-2026-41091

Microsoft · Published May 20, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Affected Products

  • Malware Protection Engine < 1.1.26040.8

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H