CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Microsoft Defender Malware Protection Engine, link-following EoP to SYSTEM (CWE-59); Engine ≤ 1.1.26030.3008; actively exploited

cve · CVE-2026-41091 single-source

Coverage
1
first 2026-05-20 → last 2026-05-25
Latest activity
2026-05-22
CVE-2026-41091, Microsoft Defender Engine link-following EoP, actively exploited
Peak priority
high
1 high
Targets
·
no sector or region stated
Sources cited
2
2 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-41091, newest first. Check the date before acting on an older one.

  • Verify Microsoft Defender Engine ≥ 1.1.26040.8 across the Windows estate. Run Get-MpComputerStatus and confirm AMEngineVersion ≥ 1.1.26040.8. Closes both CVE-2026-41091 (actively exploited LPE to SYSTEM) and CVE-2026-45584 (network RCE in Defender). For hosts with auto-updates blocked (GPO "Turn off routine remediation"), push the Engine signature update manually (MSRC CVE-2026-41091).
    2026-05-20CVE-2026-41091 +1
  • Verify Defender Antimalware Engine >= 1.1.26040.8 (LPE fix) AND Platform >= 4.18.26040.7 (DoS fix), CVE-2026-41091 (SYSTEM LPE via MsMpEng.exe link-following) confirmed ITW; run Get-MpComputerStatus | Select AMEngineVersion, AMProductVersion on all Windows endpoints. AMProductVersion alone does not confirm the LPE is patched, check AMEngineVersion. Environments using delayed-approval WSUS/Intune update rings may not have received the out-of-band engine update yet, approve immediately.
    2026-05-20CVE-2026-41091 +1

Story timeline

  1. 2026-05-20CVE-2026-41091, Microsoft Defender Engine link-following EoP, actively exploited
    trending-vulnerabilities
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Privilege EscalationExploitation for Privilege Escalation

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-05-20/cve-2026-41091-microsoft-defender-engine-link-following-eop · ATT&CK page ↗

Entries about Microsoft Defender Malware Protection Engine, link-following EoP to SYSTEM (CWE-59); Engine ≤ 1.1.26030.3008; actively exploited (1)

2026-05-20 · view entry permalink →

HIGHCVE-2026-41091 +1exploitedupdated

Microsoft added CVE-2026-41091 to the MSRC update guide on 2026-05-19 with both exploited=Yes and publiclyDisclosed=Yes. The flaw is an improper link resolution before file access (CWE-59, "link following") in the Microsoft Malware Protection Engine that allows an authorised local attacker to elevate to SYSTEM. CVSS 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Vulnerable Engine builds: ≤ 1.1.26030.3008; fixed in Engine 1.1.26040.8. Microsoft normally pushes Engine updates automatically through Windows Update and the Defender signature channel; endpoints where automatic Engine updates are blocked (air-gapped, change-controlled, or explicitly disabled) remain exposed until manually patched. The class makes this attractive as a stage-2 LPE gadget after any initial-access foothold: a SYSTEM shell on a Defender-managed host grants LSASS access, service-creation persistence, and lateral movement.

Hunt for unexpected junction / hard-link creation events (Sysmon EID 11 with TargetFilename pointing to privileged Defender / Program Files paths) coinciding with Defender scans. Confirm Get-MpComputerStatus returns an AMEngineVersion ≥ 1.1.26040.8 across the estate; for any host where the GPO "Turn off routine remediation" disables auto-remediation, push the Engine update manually.

Microsoft added CVE-2026-41091 to the MSRC update guide on 2026-05-19 with both exploited=Yes and publiclyDisclosed=Yes.

UPDATE (originally covered 2026-05-20): Both Microsoft Defender vulnerabilities confirmed as actively exploited in the wild in a combined out-of-band engine update (The Hacker News, 2026-05-21).

ctipilot v2 brief (migrated)
Updaterun 2026-05-22-5b90d5a1actionscvesevidencesourcesbody

Both Microsoft Defender vulnerabilities confirmed as actively exploited in the wild in a combined out-of-band engine update (The Hacker News, 2026-05-21). CVE-2026-41091 (CVSS 7.8, CWE-59 improper link resolution / link following in MsMpEng.exe) allows an authorized local standard-user to abuse Defender's privileged process's symbolic-link resolution during file-system operations to elevate to NT AUTHORITY\SYSTEM (T1068 Exploitation for Privilege Escalation). CVE-2026-45498 (CVSS 4.0, local DoS) was exploited alongside CVE-2026-41091 in observed attacks. Fixed: CVE-2026-41091 (LPE) requires Defender Antimalware Engine >= 1.1.26040.8; CVE-2026-45498 (DoS) requires Antimalware Platform >= 4.18.26040.7. Verify both via Get-MpComputerStatus | Select AMEngineVersion, AMProductVersion; environments with delayed WSUS/Intune update rings must confirm the engine version, not only the platform version, to confirm the LPE patch is applied. Environments with delayed auto-update channels (WSUS/Intune with manual approval) or air-gapped Defender deployments are at risk. Hunt signal: Sysmon EID 1 for SYSTEM-level process spawns from MsMpEng.exe as parent.

vulnerability20 May 05:00Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • msrc.microsoft.com1 (50%)
  • thehackernews.com1 (50%)