Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
Briefly

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
Microsoft released patches for two Microsoft Defender vulnerabilities and warned they were exploited in the wild as zero-days. CVE-2026-41091 is a link-following issue that can let an authorized attacker elevate privileges locally to System, with a CVSS score of 7.8. CVE-2026-45498 is a denial-of-service flaw with a CVSS score of 4.0. The fixes are addressed in Microsoft Defender Antimalware Platform version 4.18.26040.7. Microsoft stated that systems with Microsoft Defender disabled are not exploitable even if Defender files remain on disk. Microsoft also noted public disclosure and detected in-the-wild exploitation without providing further details. CISA added both flaws to its Known Exploited Vulnerabilities list and urged patching by June 3.
"Microsoft this week released patches for two vulnerabilities in Defender, warning they have been exploited in the wild as zero-days. The first, tracked as CVE-2026-41091 (CVSS score of 7.8), is described as a link-following issue that allows attackers to elevate their privileges to System. "Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally," Microsoft notes in its bare-bones advisory."
"The second bug, tracked as CVE-2026-45498 (CVSS score of 4.0), is a denial-of-service (DoS) flaw. Microsoft addressed the two security defects in Microsoft Defender Antimalware Platform version 4.18.26040.7. According to the company, systems with Microsoft Defender disabled are not exploitable, even though Defender's files remain on disk. The company warned that both vulnerabilities have been publicly disclosed and that in-the-wild exploitation was detected, but did not provide further details."
"On Wednesday, the US cybersecurity agency CISA added both flaws to its Known Exploited Vulnerabilities ( KEV) list, urging federal agencies to patch them by June 3. The fresh Defender bugs were added to CISA's KEV list alongside five other issues, all disclosed over half a decade ago. The oldest of the five is CVE-2008-4250, a remote code execution (RCE) weakness in the Server service of older Windows iterations that can be exploited via crafted RPC requests."
Read at SecurityWeek
Unable to calculate read time
[
|
]