CVE-2026-45584
Microsoft Malware Protection Engine vulnerability analysis and mitigation

Overview

CVE-2026-45584 is a heap-based buffer overflow vulnerability in Microsoft Defender (specifically the Microsoft Malware Protection Engine) that allows an unauthenticated remote attacker to execute arbitrary code over a network. It affects Microsoft Malware Protection Engine versions from 1.1.26030.3008 up to (but not including) 1.1.26040.8. The vulnerability was published on May 20, 2026, with a patch released as part of Microsoft's May 2026 security update cycle. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, MSRC).

Technical details

The root cause is a heap-based buffer overflow (CWE-122) in the Microsoft Malware Protection Engine, which is the scanning component underlying Microsoft Defender. An attacker can trigger the overflow by sending specially crafted content over the network that the engine processes during malware scanning — a particularly dangerous attack surface since the engine automatically inspects incoming files and network traffic without user interaction. The attack vector is network-based, requires no privileges and no user interaction, though attack complexity is rated High, suggesting some precondition or timing requirement must be met. A GitHub repository claiming to be a PoC was identified but assessed as non-exploitable, containing only a minimal README and binary artifacts with no actual exploit code (GitHub Advisory, Feedly).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code in the context of the Microsoft Malware Protection Engine service, which typically runs with elevated system privileges. This results in high impact to confidentiality, integrity, and availability of the affected system, potentially enabling full system compromise, data exfiltration, installation of persistent malware, or lateral movement within a network. The RedSun malware family has been reported to have weaponized this vulnerability in live intrusions, underscoring the severity of real-world impact (Qualys Blog, TechTimes).

Exploitation steps

  1. Reconnaissance: Identify systems running Microsoft Defender with Malware Protection Engine versions between 1.1.26030.3008 and 1.1.26040.7 using network scanning tools or vulnerability scanners such as Qualys.
  2. Craft malicious payload: Prepare a specially crafted file or network payload (e.g., a malformed archive, executable, or document) designed to trigger a heap-based buffer overflow when parsed by the Microsoft Malware Protection Engine.
  3. Deliver payload: Transmit the crafted content to the target system over the network — this could be via email attachment, SMB share, HTTP download, or any other vector that causes Defender to automatically scan the content without user interaction.
  4. Trigger engine processing: The Malware Protection Engine automatically scans the incoming content, triggering the heap overflow during parsing of the malicious payload.
  5. Achieve code execution: The overflow corrupts heap memory in a controlled manner, redirecting execution flow to attacker-controlled code running in the context of the Defender/MsMpEng service (typically SYSTEM or high-privilege context), enabling full system compromise (GitHub Advisory, MSRC).

Indicators of compromise

  • Process: Unusual child processes spawned by MsMpEng.exe (the Malware Protection Engine process), such as cmd.exe, powershell.exe, curl, or wget; unexpected network connections originating from MsMpEng.exe.
  • Network: Outbound connections from the Defender engine process to unknown or suspicious external IP addresses; unusual inbound network traffic delivering malformed files or archives to endpoints.
  • File System: Unexpected files dropped in system directories or temp folders by the MsMpEng.exe process; presence of RedSun malware artifacts or unfamiliar executables created around the time of exploitation.
  • Logs: Windows Event Logs showing crashes or faults in MsMpEng.exe (Event ID 1000/1001 Application Error); Windows Defender operational logs showing scan failures or engine crashes on specific files; unexpected engine version downgrades or tampering with Defender update mechanisms.
  • Registry: Modifications to Defender configuration keys (e.g., HKLM\SOFTWARE\Microsoft\Windows Defender) that disable real-time protection or alter engine behavior post-exploitation (TechTimes, Qualys Blog).

Mitigation and workarounds

Microsoft released a patch for this vulnerability as part of the May 2026 security update cycle (released May 12, 2026). Organizations should update the Microsoft Malware Protection Engine to version 1.1.26040.8 or later; systems running versions 1.1.26030.3008 through 1.1.26040.7 are vulnerable (MSRC). On most systems, the Malware Protection Engine updates automatically via Windows Update — administrators should verify the engine version is current and ensure automatic updates are not blocked. As a temporary measure prior to patching, restricting network exposure of vulnerable endpoints and monitoring for anomalous MsMpEng.exe behavior is advised (Qualys Blog).

Community reactions

The vulnerability received significant media coverage given its active exploitation status and association with the RedSun malware. The Hacker News reported Microsoft's warning about two actively exploited Defender flaws, and CSO Online, Help Net Security, and Heise covered the out-of-band patch and exploitation context (The Hacker News, Help Net Security, Heise). Qualys published a blog post specifically addressing RedSun malware risk in Microsoft Defender and urging immediate mitigation even before patching (Qualys Blog). Social media discussion on Mastodon (via VulnDB and other accounts) and Reddit's CVEWatch community highlighted the vulnerability as a top trending CVE for the week of May 22, 2026. SANS ISC also covered the vulnerability in a podcast episode, reflecting broad community awareness (SANS ISC).

Additional resources


SourceThis report was generated using AI

Related Microsoft Malware Protection Engine vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45584HIGH8.1
  • Microsoft Malware Protection Engine logoMicrosoft Malware Protection Engine
  • cpe:2.3:a:microsoft:malware_protection_engine
NoYesMay 20, 2026
CVE-2026-55012HIGH7.8
  • Microsoft Malware Protection Engine logoMicrosoft Malware Protection Engine
  • cpe:2.3:a:microsoft:malware_protection_engine
NoYesJul 14, 2026
CVE-2026-55011HIGH7.8
  • Microsoft Malware Protection Engine logoMicrosoft Malware Protection Engine
  • cpe:2.3:a:microsoft:malware_protection_engine
NoYesJul 14, 2026
CVE-2026-41091HIGH7.8
  • Microsoft Defender Antimalware Platform logoMicrosoft Defender Antimalware Platform
  • cpe:2.3:a:microsoft:defender_antimalware_platform
YesYesMay 20, 2026
CVE-2026-50656HIGH7
  • Microsoft Malware Protection Engine logoMicrosoft Malware Protection Engine
  • cpe:2.3:a:microsoft:malware_protection_engine
NoYesJun 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management