
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55012 is an integer overflow/heap-based buffer overflow vulnerability in Microsoft Defender's Malware Protection Engine that allows an unauthorized local attacker to execute arbitrary code. Disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday (which addressed a record 570 vulnerabilities), it affects Microsoft Malware Protection Engine versions from 1.1.0.0 up to (excluding) 1.1.26060.3008 (MSRC Advisory, BleepingComputer). The vulnerability carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (MSRC Advisory).
The vulnerability is rooted in an integer overflow or wraparound (CWE-190) in Microsoft Defender's Malware Protection Engine that leads to a heap-based buffer overflow (CWE-122), classified under CAPEC-92 (Forced Integer Overflow) (MSRC Advisory). An attacker can exploit this flaw locally without requiring any special privileges, though user interaction is required to trigger the vulnerable code path — likely by causing the engine to scan a specially crafted malicious file. The attack vector is local (AV:L), with low complexity (AC:L) and no privileges required (PR:N), but user interaction (UI:R) is a prerequisite, limiting the attack surface compared to fully remote or automated exploitation scenarios.
Successful exploitation grants an attacker the ability to execute arbitrary code with the same privileges as the Microsoft Malware Protection Engine process, which typically runs with elevated system-level permissions. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive data, modify system files, or cause denial of service on the affected endpoint (MSRC Advisory). Given the engine's privileged context, exploitation could facilitate privilege escalation and serve as a foothold for lateral movement within a network.
MsMpEng.exe), such as cmd.exe, powershell.exe, or network utilities.MsMpEng.exe; Windows Error Reporting (WER) logs referencing heap corruption or access violations in the Malware Protection Engine.MsMpEng.exe to unknown external IP addresses or domains, which would be anomalous for the antimalware engine process.Microsoft has released a patch via an update to the Microsoft Malware Protection Engine; updating to version 1.1.26060.3008 or later fully remediates the vulnerability (MSRC Advisory). On most systems, the Malware Protection Engine updates automatically through Windows Update, so ensuring automatic updates are enabled is the primary remediation step. As an interim measure, limiting local access to systems to authorized users only and monitoring for suspicious local activity can reduce exploitation risk.
CVE-2026-55012 was covered as part of broader reporting on Microsoft's record-breaking July 2026 Patch Tuesday, which fixed 570 vulnerabilities including three zero-days (BleepingComputer, Qualys Blog). Security researchers at Talos Intelligence and CrowdStrike published Patch Tuesday analyses covering the July 2026 release, though this specific CVE did not receive prominent individual attention given the volume of patches (Talos Blog, CrowdStrike Blog). The SANS Internet Storm Center also noted the July 2026 Patch Tuesday in its diary (SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."