
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55011 is an integer underflow (wrap or wraparound) vulnerability in Microsoft Defender's Malware Protection Engine that allows an unauthorized local attacker to execute arbitrary code. It was disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities. All versions of the Microsoft Malware Protection Engine from 1.1.0.0 up to (excluding) 1.1.26060.3008 are affected. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-191 (Integer Underflow / Wrap or Wraparound), where an arithmetic operation produces a value smaller than the minimum representable integer, causing the result to wrap around to a large positive value. In the context of Microsoft Defender's Malware Protection Engine, this flaw is triggered when the engine processes specially crafted input — such as a malicious file submitted for scanning — causing the underflow condition that can be leveraged to achieve local code execution. Exploitation requires user interaction (e.g., opening or scanning a crafted file) but does not require any special privileges, making it accessible to any local user. No public proof-of-concept code has been identified (Microsoft MSRC, Feedly).
Successful exploitation results in high confidentiality, integrity, and availability impact on the affected system, as reflected in the CVSS scoring. An attacker who triggers the vulnerability can execute arbitrary code in the context of the Malware Protection Engine process, potentially gaining control over the affected host, accessing sensitive data, or disrupting system availability. Because Microsoft Defender is present on a wide range of Windows endpoints, the affected asset scope is broad, though exploitation is constrained to local access with required user interaction (Microsoft MSRC, Feedly).
MsMpEng.exe); Windows Application Event Log entries referencing faults in mpengine.dll.MsMpEng.exe (e.g., cmd.exe, powershell.exe, wscript.exe); unexpected network connections originating from the Malware Protection Engine process.MsMpEng.exe to unknown or suspicious external IP addresses following a file scan event.Microsoft has released a patch updating the Microsoft Malware Protection Engine to version 1.1.26060.3008 or later, which resolves this vulnerability. On most systems, the engine updates automatically via Windows Update or Microsoft Update without requiring user intervention or a system restart. Administrators should verify that automatic updates are enabled and confirm the installed engine version is at or above 1.1.26060.3008. No configuration-based workaround is available; patching is the only remediation (Microsoft MSRC, Feedly).
CVE-2026-55011 was covered as part of broader reporting on Microsoft's record-breaking July 2026 Patch Tuesday, which fixed 570 vulnerabilities including three zero-days. Security outlets including BleepingComputer, CyberSecurityNews, Qualys, Cisco Talos, and CrowdStrike published Patch Tuesday roundups that referenced this CVE among the broader set of Defender-related fixes. The vulnerability did not receive significant standalone attention, as it was not actively exploited and required local access with user interaction, making it lower priority compared to the zero-days patched in the same release (BleepingComputer, Talos, Qualys).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."