V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2026-41091
CVE
High KEVConfirmedExploit available

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges lo…

CVSS
7.8
High
EPSS
0.08
p92
Published
2026-01-01
Updated
2026-05-20
Description

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Tags · CWE
KEV
CWE-59
CAPEC-17
CAPEC-35
CAPEC-76
CAPEC-132
Affected products
Malware_protection_engine 1.1.26030.3008–1.1.26040.8
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2026-01-01
Published
2026-05-20
Added to KEV
2026-05-20
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.080 · p92
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-59
└ via CAPEC-35 · CWE-59
└ via CAPEC-132 · CWE-59
└ via CAPEC-35 · CWE-59
Known exploits — Сканер-ВС
CVE-2026-41091
github-poc · https://github.com/0xBlackash/CVE-2026-41091
Enterprise
Affected software
ProductVendorStatus
malware_protection_engine*Exploited