---
schema: 1
kind: vulnerability
title: "CVE-2026-41091 — Microsoft Defender Engine link-following EoP, actively exploited"
headline: "CVE-2026-41091 — Microsoft Defender Engine link-following EoP, actively exploited"
summary: >
  CVE-2026-41091 — Microsoft Defender Engine link-following EoP confirmed exploited in the wild
  and publicly disclosed. Engine ≤1.1.26030.3008 grants SYSTEM via CWE-59 link following; Engine
  1.1.26040.8 auto-remediates via signature channel (MSRC CVE-2026-41091, 2026-05-19). Air-gapped
  or auto-update-blocked endpoints remain vulnerable.
discovered_at: "2026-05-20T05:00:06Z"
updated_at: "2026-05-22T05:00:07Z"
event_date: 2026-05-19
run_id: 2026-05-20-a0f7b07f
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - lpe
  - priv-esc
  - actively-exploited
  - patch-available
regions:
  - global
sectors: []
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-41091
    cvss: "7.8"
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status:
      - exploited
      - patch-available
  - id: CVE-2026-45498
    cvss: "4.0"
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091"
    publisher: "MSRC CVE-2026-41091, 2026-05-19"
    role: primary
  - url: "https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html"
    publisher: "The Hacker News, 2026-05-21"
    role: primary
closed_sources: []
evidence:
  - quote: "Microsoft added CVE-2026-41091 to the MSRC update guide on 2026-05-19 with both exploited=Yes and publiclyDisclosed=Yes."
    publisher: ctipilot v2 brief (migrated)
  - quote: "UPDATE (originally covered 2026-05-20): Both Microsoft Defender vulnerabilities confirmed as actively exploited in the wild in a combined out-of-band engine update (The Hacker News, 2026-05-21)."
    publisher: ctipilot v2 brief (migrated)
verification: single-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Verify Microsoft Defender Engine ≥ 1.1.26040.8 across the Windows estate.** Run `Get-MpComputerStatus` and confirm `AMEngineVersion` ≥ 1.1.26040.8. Closes both CVE-2026-41091 (actively exploited LPE to SYSTEM) and CVE-2026-45584 (network RCE in Defender). For hosts with auto-updates blocked (GPO \"Turn off routine remediation\"), push the Engine signature update manually ([MSRC CVE-2026-41091](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091))."
  - "**Verify Defender Antimalware Engine >= 1.1.26040.8 (LPE fix) AND Platform >= 4.18.26040.7 (DoS fix)** — CVE-2026-41091 (SYSTEM LPE via MsMpEng.exe link-following) confirmed ITW; run `Get-MpComputerStatus | Select AMEngineVersion, AMProductVersion` on all Windows endpoints. `AMProductVersion` alone does not confirm the LPE is patched — check `AMEngineVersion`. Environments using delayed-approval WSUS/Intune update rings may not have received the out-of-band engine update yet — approve immediately."
updates:
  - at: "2026-05-22T05:00:07Z"
    run_id: 2026-05-22-5b90d5a1
    type: update
    summary: >
      UPDATE (originally covered 2026-05-20): Both Microsoft Defender vulnerabilities confirmed as
      actively exploited in the wild in a combined out-of-band engine update (The Hacker News,
      2026-05-21).
    fields:
      - actions
      - cves
      - evidence
      - sources
      - body
    merged_from: 2026-05-22/microsoft-defender-cve-2026-41091-cve-2026-45498-both-cves-c
migrated_from: briefs/2026-05-20.md
---

Microsoft added CVE-2026-41091 to the [MSRC update guide on 2026-05-19](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091) with both `exploited=Yes` and `publiclyDisclosed=Yes`. The flaw is an **improper link resolution before file access** (CWE-59, "link following") in the **Microsoft Malware Protection Engine** that allows an authorised local attacker to elevate to SYSTEM. CVSS 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Vulnerable Engine builds: ≤ 1.1.26030.3008; fixed in Engine 1.1.26040.8. Microsoft normally pushes Engine updates automatically through Windows Update and the Defender signature channel — endpoints where automatic Engine updates are blocked (air-gapped, change-controlled, or explicitly disabled) remain exposed until manually patched. The class makes this attractive as a stage-2 LPE gadget after any initial-access foothold: a SYSTEM shell on a Defender-managed host grants LSASS access, service-creation persistence, and lateral movement.

Hunt for unexpected junction / hard-link creation events (Sysmon EID 11 with `TargetFilename` pointing to privileged Defender / Program Files paths) coinciding with Defender scans. Confirm `Get-MpComputerStatus` returns an `AMEngineVersion` ≥ 1.1.26040.8 across the estate; for any host where the GPO "Turn off routine remediation" disables auto-remediation, push the Engine update manually.

## Update — 2026-05-22T05:00:07Z

Both Microsoft Defender vulnerabilities confirmed as actively exploited in the wild in a combined out-of-band engine update ([The Hacker News, 2026-05-21](https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html)). CVE-2026-41091 (CVSS 7.8, CWE-59 improper link resolution / link following in `MsMpEng.exe`) allows an authorized local standard-user to abuse Defender's privileged process's symbolic-link resolution during file-system operations to elevate to `NT AUTHORITY\SYSTEM` (`T1068 Exploitation for Privilege Escalation`). CVE-2026-45498 (CVSS 4.0, local DoS) was exploited alongside CVE-2026-41091 in observed attacks. Fixed: CVE-2026-41091 (LPE) requires Defender Antimalware Engine >= 1.1.26040.8; CVE-2026-45498 (DoS) requires Antimalware Platform >= 4.18.26040.7. Verify both via `Get-MpComputerStatus | Select AMEngineVersion, AMProductVersion` — environments with delayed WSUS/Intune update rings must confirm the engine version, not only the platform version, to confirm the LPE patch is applied. Environments with delayed auto-update channels (WSUS/Intune with manual approval) or air-gapped Defender deployments are at risk. Hunt signal: Sysmon EID 1 for SYSTEM-level process spawns from `MsMpEng.exe` as parent.
