
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-41091 is a local privilege escalation vulnerability in Microsoft Defender's Malware Protection Engine caused by improper symbolic link (symlink) resolution before file access (CWE-59). It allows an authenticated attacker with low privileges to escalate to SYSTEM-level access without any user interaction. The vulnerability affects Microsoft Malware Protection Engine versions 1.1.26030.3008 through 1.1.26040.7, and was publicly disclosed on May 20, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (MSRC, GitHub Advisory, CISA KEV).
The root cause is CWE-59 (Improper Link Resolution Before File Access — 'Link Following'), where Microsoft Defender's Malware Protection Engine fails to properly validate symbolic links during its remediation workflow before accessing files. An attacker with a local foothold and low-level privileges can plant a crafted symlink in a location that Defender's remediation process follows, causing the engine to operate on attacker-controlled targets with elevated (SYSTEM) privileges. This technique — dubbed "RedSun" by researchers — abuses Defender's own remediation logic to overwrite protected system files. No user interaction is required, and attack complexity is low, making it straightforward to exploit once local access is obtained (MSRC, RedSun Technical Write-up, Malware News).
Successful exploitation grants the attacker SYSTEM-level privileges on the compromised host, resulting in complete compromise of confidentiality, integrity, and availability. An attacker who has already gained initial access with low privileges — for example, via phishing or another vulnerability — can use this flaw to fully take over the system, overwrite protected system files, install persistent backdoors, disable security controls, and pivot laterally within the network. The vulnerability is particularly dangerous as a post-exploitation tool in multi-stage attack chains (MSRC, Help Net Security, CISA KEV).
Get-MpComputerStatus in PowerShell or by inspecting Defender's engine version in Windows Security settings.C:\Windows\System32) with timestamps inconsistent with legitimate updates; presence of CVE-2026-41091.cpp or compiled exploit binaries on disk.MsMpEng.exe (Defender's engine process) such as cmd.exe, powershell.exe, or other shells; processes running as SYSTEM that were initiated by low-privileged user sessions.Get-MpComputerStatus).Microsoft released a patch in the May 2026 security update cycle; organizations should update Microsoft Malware Protection Engine to version 1.1.26040.8 or later immediately (MSRC). Defender typically updates its engine automatically via Windows Update or Microsoft Update, but administrators should verify the engine version via Get-MpComputerStatus in PowerShell and force an update if needed. CISA mandated that federal agencies apply mitigations by June 3, 2026 per BOD 22-01 (CISA KEV). As interim measures, restrict local user access to sensitive directories, monitor for symlink creation in Defender-monitored paths, and apply the principle of least privilege to limit the blast radius of any initial compromise.
Microsoft patched the vulnerability as part of an out-of-band update on May 20, 2026, and subsequently issued statements criticizing the public release of zero-day details before coordinated disclosure, referencing the "Nightmare Eclipse" / "Chaotic Eclipse" researcher cluster that disclosed multiple Defender vulnerabilities publicly (Security Week, The Hacker News). Microsoft initially threatened legal action against the researcher but later retracted those threats following significant industry backlash, with the community broadly criticizing Microsoft's response as disproportionate (Infosecurity Magazine, Security Week). The vulnerability received widespread coverage from BleepingComputer, Help Net Security, The Hacker News, and Malwarebytes, with the security community on Reddit and Mastodon actively discussing the dual issues of active exploitation and the disclosure controversy. The Picus Security blog published a detailed anatomical analysis of the exploit chain under the name "RoguePlanet" (Picus Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."