
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45498 is a Denial of Service (DoS) vulnerability in the Microsoft Defender Antimalware Platform, disclosed on May 20, 2026. It allows unauthenticated remote attackers to crash or disable the Defender antimalware service without any user interaction. Affected versions are all releases of the Microsoft Defender Antimalware Platform prior to 4.18.26040.7 (MSRC Advisory, GitHub Advisory). The vulnerability carries a CVSS v3.1 base score of 7.5 (High) per NVD/Feedly, reflecting its network-exploitable, no-authentication-required nature, though ENISA scores it at 4.0 (Medium) using a local attack vector (GitHub Advisory, CISA KEV).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption), with an estimated secondary classification of CWE-476 (NULL Pointer Dereference) (GitHub Advisory). The vulnerability can be triggered over the network with low attack complexity, requiring no privileges and no user interaction, making it trivially exploitable by any network-accessible attacker. The attack pattern is consistent with CAPEC-147 (XML Ping of the Death) and CAPEC-492 (Regular Expression Exponential Blowup), suggesting the flaw may involve malformed or resource-exhausting input to the Defender scanning engine (Feedly). No detailed public technical write-up or proof-of-concept code has been confirmed as of the time of this report.
Successful exploitation renders the Microsoft Defender Antimalware Platform unavailable, effectively disabling endpoint protection on affected systems (CISA KEV). There is no direct confidentiality or integrity impact from this vulnerability itself; however, disabling Defender creates a significant secondary risk by leaving systems unprotected against malware, ransomware, and other threats (Help Net Security). In environments where Defender is the primary or sole endpoint protection layer, exploitation could facilitate follow-on attacks by removing a critical defensive control.
%ProgramData%\Microsoft\Windows Defender\Support\.MsMpEng.exe process or repeated restarts of the Defender service process; Defender reporting as disabled or non-functional in Windows Security Center.Microsoft has released a patch in Microsoft Defender Antimalware Platform version 4.18.26040.7 and later; organizations should update immediately (MSRC Advisory). Because Defender typically updates automatically via Windows Update, administrators should verify that automatic updates are enabled and confirm the installed platform version. CISA mandated that federal agencies apply mitigations by June 3, 2026 per BOD 22-01 guidance; organizations unable to patch should consider discontinuing use of the affected product or implementing compensating controls such as alternative endpoint protection (CISA KEV). No specific configuration-based workaround has been published by Microsoft.
Microsoft issued an out-of-band security update and publicly warned of active exploitation of this vulnerability alongside the related CVE-2026-41091, drawing significant media attention (BleepingComputer, The Hacker News). The vulnerability was linked to a researcher known as "Nightmare Eclipse" (or "Chaotic Eclipse"), sparking a high-profile public dispute: Microsoft initially threatened legal action against the researcher for uncoordinated zero-day disclosure, then retracted those threats following significant industry backlash (Security Week, Infosecurity Magazine). The r/sysadmin and r/cybersecurity communities on Reddit discussed the dual impact of the vulnerability and the disclosure controversy extensively, with sysadmins expressing frustration at Defender itself becoming a significant attack surface (Reddit). Check Point Research and Recorded Future both highlighted this CVE in their May 2026 threat intelligence reports as a high-priority patching target (Check Point Research, Recorded Future).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."