
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45584 is a heap-based buffer overflow vulnerability in Microsoft Defender (specifically the Microsoft Malware Protection Engine) that allows an unauthenticated remote attacker to execute arbitrary code over a network. It affects Microsoft Malware Protection Engine versions from 1.1.26030.3008 up to (but not including) 1.1.26040.8. The vulnerability was published on May 20, 2026, with a patch released as part of Microsoft's May 2026 security update cycle. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, MSRC).
The root cause is a heap-based buffer overflow (CWE-122) in the Microsoft Malware Protection Engine, which is the scanning component underlying Microsoft Defender. An attacker can trigger the overflow by sending specially crafted content over the network that the engine processes during malware scanning — a particularly dangerous attack surface since the engine automatically inspects incoming files and network traffic without user interaction. The attack vector is network-based, requires no privileges and no user interaction, though attack complexity is rated High, suggesting some precondition or timing requirement must be met. A GitHub repository claiming to be a PoC was identified but assessed as non-exploitable, containing only a minimal README and binary artifacts with no actual exploit code (GitHub Advisory, Feedly).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code in the context of the Microsoft Malware Protection Engine service, which typically runs with elevated system privileges. This results in high impact to confidentiality, integrity, and availability of the affected system, potentially enabling full system compromise, data exfiltration, installation of persistent malware, or lateral movement within a network. The RedSun malware family has been reported to have weaponized this vulnerability in live intrusions, underscoring the severity of real-world impact (Qualys Blog, TechTimes).
MsMpEng.exe (the Malware Protection Engine process), such as cmd.exe, powershell.exe, curl, or wget; unexpected network connections originating from MsMpEng.exe.MsMpEng.exe process; presence of RedSun malware artifacts or unfamiliar executables created around the time of exploitation.MsMpEng.exe (Event ID 1000/1001 Application Error); Windows Defender operational logs showing scan failures or engine crashes on specific files; unexpected engine version downgrades or tampering with Defender update mechanisms.HKLM\SOFTWARE\Microsoft\Windows Defender) that disable real-time protection or alter engine behavior post-exploitation (TechTimes, Qualys Blog).Microsoft released a patch for this vulnerability as part of the May 2026 security update cycle (released May 12, 2026). Organizations should update the Microsoft Malware Protection Engine to version 1.1.26040.8 or later; systems running versions 1.1.26030.3008 through 1.1.26040.7 are vulnerable (MSRC). On most systems, the Malware Protection Engine updates automatically via Windows Update — administrators should verify the engine version is current and ensure automatic updates are not blocked. As a temporary measure prior to patching, restricting network exposure of vulnerable endpoints and monitoring for anomalous MsMpEng.exe behavior is advised (Qualys Blog).
The vulnerability received significant media coverage given its active exploitation status and association with the RedSun malware. The Hacker News reported Microsoft's warning about two actively exploited Defender flaws, and CSO Online, Help Net Security, and Heise covered the out-of-band patch and exploitation context (The Hacker News, Help Net Security, Heise). Qualys published a blog post specifically addressing RedSun malware risk in Microsoft Defender and urging immediate mitigation even before patching (Qualys Blog). Social media discussion on Mastodon (via VulnDB and other accounts) and Reddit's CVEWatch community highlighted the vulnerability as a top trending CVE for the week of May 22, 2026. SANS ISC also covered the vulnerability in a podcast episode, reflecting broad community awareness (SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."