Skip to main content

CVE detail

CVE-2026-41091

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · HighBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
23 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
2
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
23 source links · newest first
  • ploit targeting Microsoft Defender that leads to local privilege escalation. Chaotic Eclipse also disclosed BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498), and RedSun (CVE-2026-41091) zero-days. The disclosures are believed to stem from a dispute with Microsoft over the vulnerability reporting process. In early June, Chaotic Eclipse released a

    newssecurityaffairs.comJul 15, 2026, 4:57 PM
  • The privilege escalation vulnerability tracked as CVE-2026-50656 has been patched with a Microsoft Malware Protection Engine update.

    newswww.securityweek.comJul 9, 2026, 10:28 AM
  • Microsoft says it’s working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.

    newswww.malwarebytes.comJun 18, 2026, 12:58 PM
  • Microsoft confirmed the RoguePlanet Defender zero-day (CVE-2026-50656), a privilege escalation flaw, and is developing a security patch. Microsoft has acknowledged the RoguePlanet zero-day affecting Microsoft Defender, tracked as CVE-2026-50656 (CVSS score of 7.8). The vulnerability allows privilege escalation through the Microsoft Malware Protection Engine. The company stated it is aware of the issue and is […]

    newssecurityaffairs.comJun 18, 2026, 9:21 AM
  • The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.

    newswww.securityweek.comJun 17, 2026, 9:41 AM
  • 15th June – Threat Intelligence ReportCheck Point Research

    ysts, this breach is part of a larger wave of attacks targeting more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution. Check Point IPS provides protection against this threat (Oracle PeopleSoft Enterprise PeopleTools Server-Side Request Forgery (C

    vendorresearch.checkpoint.comJun 15, 2026, 1:40 PM
  • GreatXML bypasses BitLocker via Defender offline scan artifacts, giving SYSTEM shell in Recovery Mode. No patch exists. Any machine that ran an offline scan is vulnerable. On June 10, security researcher Chaotic Eclipse (aka Nightmare Eclipse) published a new working exploit dubbed GreatXML that bypasses BitLocker and opens a command shell with full SYSTEM privileges […]

    newssecurityaffairs.comJun 11, 2026, 10:58 AM
  • Exploiting a race condition in Microsoft Defender, the exploit leads to local privilege escalation to SYSTEM.

    newswww.securityweek.comJun 10, 2026, 11:44 AM
  • The researcher Chaotic Eclipse released a PoC for the RoguePlanet Microsoft Defender zero-day, which can grant SYSTEM privileges on fully patched Windows systems. Security researcher Chaotic Eclipse, also known as Nightmare-Eclipse, has published a new proof-of-concept exploit for a RoguePlanet Microsoft Defender zero-day. The flaw relies on a race condition that can provide attackers with […]

    newssecurityaffairs.comJun 10, 2026, 9:45 AM
  • Microsoft Patch Tuesday security updates for June 2026 fix a record 208 CVEs, including one actively exploited zero-day and multiple critical RCE flaws. Microsoft Patch Tuesday security updates for June 2026 mark a record. Microsoft shipped fixes for 208 CVEs across Windows, Office, Azure, Exchange, Hyper-V, Secure Boot, BitLocker, and a range of AI tooling. […]

    newssecurityaffairs.comJun 9, 2026, 10:55 PM
  • y to respond without out-of-cycle patches. At time of writing, Microsoft has provided mitigation advice and patches for CVE-2026-33825 , CVE-2026-45585 , CVE-2026-45498 , and CVE-2026-41091 , leaving only two elevation of privilege vulnerabilities unpatched, known as MiniPlasma and GreenPlasma. However, a recent blog post by Nightmare Eclipse with the

    vendorwww.rapid7.comJun 9, 2026, 9:04 PM
  • be the flaw known as Bitskrieg and a collaboration between Chaotic Eclipse (Nightmare Eclipse) and Jonas L . Important CVE-2026-49160 | HTTP.sys Denial of Service Vulnerability CVE-2026-49160 is a denial of service (DoS) vulnerability affecting HTTP.sys. It received a CVSSv3 score of 7.5 and is rated as important. It was assessed as “Exploitation More

    vendorwww.tenable.comJun 9, 2026, 6:19 PM
  • The June 2026 Security Update ReviewZero Day Initiative

    loser look at some of the more interesting updates for this month, starting with the bug being exploited in the wild. - CVE-2026-41091 - Microsoft Defender Elevation of Privilege Vulnerability Since Microsoft doesn’t provide info on how widespread exploitation is, we must read some tea leaves. For this patch, several different people were acknowledged,

    vendorwww.thezdi.comJun 9, 2026, 6:12 PM
  • June 2026 Patch Tuesday is now live: Record Microsoft Patch Tuesday, fresh zero-day My forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10. The Microsoft Office releases were a bit higher with 19 CVEs or so reported for the online versions. Apple did indeed … More →

    newswww.helpnetsecurity.comJun 5, 2026, 6:36 AM
  • Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.

    newswww.securityweek.comJun 3, 2026, 9:57 AM
  • In the Security Updates table, added links to the Release Notes. This is an informational change only.

    vendormsrc.microsoft.comMay 26, 2026, 2:00 PM
  • 25th May – Threat Intelligence ReportCheck Point Research

    eys, cracked WordPress accounts, and drained a crypto wallet. VULNERABILITIES AND PATCHES Microsoft published fixes for CVE-2026-41091 and CVE-2026-45498, two actively exploited Windows Defender flaws affecting the Malware Protection Engine and Defender Antimalware Platform. The first allows local privilege escalation, while the second can cause denial

    vendorresearch.checkpoint.comMay 25, 2026, 3:08 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. Earbud sensors can authenticate users by their heartbeat, study finds Researchers built a continuous authentication … More →

    newswww.helpnetsecurity.comMay 24, 2026, 8:00 AM
  • Microsoft released emergency fixes for two zero-day vulnerabilities in the malware protection components of Microsoft Defender. The flaws allow local attackers to gain system-level privileges or cause the anti-malware service to stop working correctly. Both conditions are valuable in a malware attack, first to prevent detection if the system relies only on Microsoft endpoint protection […]

    newswww.csoonline.comMay 21, 2026, 10:05 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CVE-2008-4250 (CVSS v3.1 score of 9.8) is a […]

    newssecurityaffairs.comMay 21, 2026, 8:27 PM
  • Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog. The vulnerabilities CVE-2026-41091 allows for local privilege elevation (LPE), and is caused by the Microsoft Malware Protection Engine improperly resolving links before accessing files. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft noted. CVE-2026-45498 can cause a denial-of-service (DoS) state, i.e., it can be used to prevent … More →

    newswww.helpnetsecurity.comMay 21, 2026, 10:57 AM
  • The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition.

    newswww.securityweek.comMay 21, 2026, 9:52 AM
  • No excerpt available.

    Mitigationwww.cisa.govMay 20, 2026, 1:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-50656

    Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

    CVSS 7.8 · High
    26 mentions
  • CVE-2026-17459

    A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/Extern…

    CVSS 2.1 · Low
    6 mentions
  • CVE-2026-12503

    Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `lar…

    CVSS 9.2 · Critical
    1 mention
  • CVE-2026-65069

    Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h with o…

    CVSS 4.0 · Medium
    2 mentions
  • CVE-2026-65068

    Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h wit…

    CVSS 3.8 · Low
    2 mentions
  • CVE-2026-65067

    Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h with ope…

    CVSS 3.8 · Low
    2 mentions