CVE-2026-45498
Microsoft Defender Antimalware Platform vulnerability analysis and mitigation

Overview

CVE-2026-45498 is a Denial of Service (DoS) vulnerability in the Microsoft Defender Antimalware Platform, disclosed on May 20, 2026. It allows unauthenticated remote attackers to crash or disable the Defender antimalware service without any user interaction. Affected versions are all releases of the Microsoft Defender Antimalware Platform prior to 4.18.26040.7 (MSRC Advisory, GitHub Advisory). The vulnerability carries a CVSS v3.1 base score of 7.5 (High) per NVD/Feedly, reflecting its network-exploitable, no-authentication-required nature, though ENISA scores it at 4.0 (Medium) using a local attack vector (GitHub Advisory, CISA KEV).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption), with an estimated secondary classification of CWE-476 (NULL Pointer Dereference) (GitHub Advisory). The vulnerability can be triggered over the network with low attack complexity, requiring no privileges and no user interaction, making it trivially exploitable by any network-accessible attacker. The attack pattern is consistent with CAPEC-147 (XML Ping of the Death) and CAPEC-492 (Regular Expression Exponential Blowup), suggesting the flaw may involve malformed or resource-exhausting input to the Defender scanning engine (Feedly). No detailed public technical write-up or proof-of-concept code has been confirmed as of the time of this report.

Impact

Successful exploitation renders the Microsoft Defender Antimalware Platform unavailable, effectively disabling endpoint protection on affected systems (CISA KEV). There is no direct confidentiality or integrity impact from this vulnerability itself; however, disabling Defender creates a significant secondary risk by leaving systems unprotected against malware, ransomware, and other threats (Help Net Security). In environments where Defender is the primary or sole endpoint protection layer, exploitation could facilitate follow-on attacks by removing a critical defensive control.

Exploitation steps

  1. Reconnaissance: Identify systems running Microsoft Defender Antimalware Platform versions prior to 4.18.26040.7 using network scanning tools or endpoint management telemetry. Systems with Windows Defender enabled and internet-facing services are primary targets.
  2. Craft malicious payload: Prepare a specially crafted network request or file designed to trigger uncontrolled resource consumption in the Defender scanning engine (consistent with CAPEC-147 or CAPEC-492 attack patterns such as malformed XML or regex-exhausting input).
  3. Deliver payload: Send the crafted input to the target system over the network without requiring authentication or user interaction, targeting the Defender antimalware service's network-accessible processing components.
  4. Trigger DoS condition: The Defender service crashes or becomes unresponsive due to resource exhaustion, disabling real-time protection on the endpoint.
  5. Follow-on attack: With endpoint protection disabled, deploy malware, ransomware, or other payloads that would otherwise be detected and blocked by Defender (CISA KEV, Help Net Security).

Indicators of compromise

  • Logs: Windows Event Log entries showing unexpected termination or crash of the Microsoft Defender Antimalware service (MsMpEng.exe); Event ID 7034 (service crashed unexpectedly) or Event ID 7031 in the System log.
  • Logs: Defender operational logs showing repeated scan failures, engine errors, or service restarts in %ProgramData%\Microsoft\Windows Defender\Support\.
  • Process: Absence of the MsMpEng.exe process or repeated restarts of the Defender service process; Defender reporting as disabled or non-functional in Windows Security Center.
  • Network: Unusual or malformed inbound network traffic patterns targeting endpoints shortly before Defender service disruption; repeated connection attempts from external IPs coinciding with service crashes.
  • File System: Presence of unexpected executables or scripts deployed after Defender service disruption, indicating follow-on payload delivery (CISA KEV, Help Net Security).

Mitigation and workarounds

Microsoft has released a patch in Microsoft Defender Antimalware Platform version 4.18.26040.7 and later; organizations should update immediately (MSRC Advisory). Because Defender typically updates automatically via Windows Update, administrators should verify that automatic updates are enabled and confirm the installed platform version. CISA mandated that federal agencies apply mitigations by June 3, 2026 per BOD 22-01 guidance; organizations unable to patch should consider discontinuing use of the affected product or implementing compensating controls such as alternative endpoint protection (CISA KEV). No specific configuration-based workaround has been published by Microsoft.

Community reactions

Microsoft issued an out-of-band security update and publicly warned of active exploitation of this vulnerability alongside the related CVE-2026-41091, drawing significant media attention (BleepingComputer, The Hacker News). The vulnerability was linked to a researcher known as "Nightmare Eclipse" (or "Chaotic Eclipse"), sparking a high-profile public dispute: Microsoft initially threatened legal action against the researcher for uncoordinated zero-day disclosure, then retracted those threats following significant industry backlash (Security Week, Infosecurity Magazine). The r/sysadmin and r/cybersecurity communities on Reddit discussed the dual impact of the vulnerability and the disclosure controversy extensively, with sysadmins expressing frustration at Defender itself becoming a significant attack surface (Reddit). Check Point Research and Recorded Future both highlighted this CVE in their May 2026 threat intelligence reports as a high-priority patching target (Check Point Research, Recorded Future).

Additional resources


SourceThis report was generated using AI

Related Microsoft Defender Antimalware Platform vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-41091HIGH7.8
  • Microsoft Defender Antimalware Platform logoMicrosoft Defender Antimalware Platform
  • cpe:2.3:a:microsoft:defender_antimalware_platform
YesYesMay 20, 2026
CVE-2026-33825HIGH7.8
  • Microsoft Defender Antimalware Platform logoMicrosoft Defender Antimalware Platform
  • cpe:2.3:a:microsoft:defender_antimalware_platform
YesYesApr 14, 2026
CVE-2026-45498HIGH7.5
  • Microsoft Defender Antimalware Platform logoMicrosoft Defender Antimalware Platform
  • cpe:2.3:a:microsoft:defender_antimalware_platform
YesYesMay 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management