
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45647 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Microsoft Defender for Endpoint for macOS that allows a locally authorized attacker to escalate privileges. It affects versions from 101.0.0 up to (but not including) 101.26042.0011. The vulnerability was disclosed on June 9, 2026, as part of Microsoft's June 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 7.0 (High) (MSRC, Feedly).
The vulnerability is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition), where a window exists between the time a resource is checked and the time it is used, allowing an attacker to manipulate the resource in between. An attacker with low-privileged local access can exploit this race condition — potentially via symbolic link manipulation (CAPEC-27) or classic TOCTOU techniques (CAPEC-29) — to gain elevated privileges on the affected macOS system. Exploitation requires local access and low privileges, but no user interaction, and has high attack complexity due to the timing-dependent nature of race condition exploitation (Feedly, MSRC).
Successful exploitation grants an attacker high-level (likely root or system-level) privileges on the affected macOS endpoint, resulting in high confidentiality, integrity, and availability impact. A low-privileged local user could leverage this to fully compromise the system, access sensitive data, tamper with security configurations, or disable endpoint protection mechanisms. The scope is limited to the affected system (unchanged scope), but privilege escalation could facilitate further lateral movement within a network (Feedly).
There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2026-45647. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.05%, reflecting a low near-term exploitation probability. The NVD SSVC assessment also classifies exploitation as "none" at this time (Feedly, MSRC).
Microsoft has released a patch in Microsoft Defender for Endpoint for Mac version 101.26042.0011 or later, distributed as part of the June 2026 Patch Tuesday update cycle. Organizations should prioritize updating all macOS systems running Defender for Endpoint to this version or higher. As interim measures, limit local administrative access on macOS endpoints and monitor for suspicious privilege escalation activity. No configuration-based workaround has been published; patching is the recommended remediation (MSRC, Feedly).
CVE-2026-45647 was covered as part of broader June 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Zero Day Initiative, and CyberSecurityNews, though it did not receive individual focused attention given the large volume (198–206 vulnerabilities) patched in that cycle. No specific researcher commentary or notable social media discussion has been identified for this CVE specifically (BleepingComputer, Rapid7, ZDI).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."