Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

https://www.securityweek.com/wp-content/uploads/2026/05/Microsoft-Defender.jpg

Microsoft this week released patches for two vulnerabilities in Defender, warning they have been exploited in the wild as zero-days.

The first, tracked as CVE-2026-41091 (CVSS score of 7.8), is described as a link-following issue that allows attackers to elevate their privileges to System.

“Improper link resolution before file access (‘link following’) in Microsoft Defender allows an authorized attacker to elevate privileges locally,” Microsoft notes in its bare-bones advisory.

The second bug, tracked as CVE-2026-45498 (CVSS score of 4.0), is a denial-of-service (DoS) flaw.

Microsoft addressed the two security defects in Microsoft Defender Antimalware Platform version 4.18.26040.7. According to the company, systems with Microsoft Defender disabled are not exploitable, even though Defender’s files remain on disk.

The company warned that both vulnerabilities have been publicly disclosed and that in-the-wild exploitation was detected, but did not provide further details.

Advertisement. Scroll to continue reading.

According to a postby Microsoft MVP...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE