---
schema: 1
kind: vulnerability
title: CVE-2026-45584 — Microsoft Defender Engine heap-buffer-overflow RCE over network
headline: CVE-2026-45584 — Microsoft Defender Engine heap-buffer-overflow RCE over network
summary: "Microsoft also disclosed CVE-2026-45584 on 2026-05-19 — a heap-based buffer overflow in the Defender Engine reachable over the network (AV:N), allowing unauthenticated code execution in the Defender process context. CVSS 8.1; no exploitation observed at disclosure, no public PoC."
discovered_at: "2026-05-20T05:00:07Z"
event_date: 2026-05-19
run_id: 2026-05-20-a0f7b07f
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-45584
    cvss: "8.1"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45584"
    publisher: "MSRC CVE-2026-45584, 2026-05-19"
    role: primary
closed_sources: []
evidence: []
verification: single-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-20.md
---

Microsoft also disclosed CVE-2026-45584 on [2026-05-19](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45584) — a heap-based buffer overflow in the Defender Engine reachable over the network (AV:N), allowing unauthenticated code execution in the Defender process context. CVSS 8.1; no exploitation observed at disclosure, no public PoC. The same Engine update (≥ 1.1.26040.8) that closes CVE-2026-41091 also closes CVE-2026-45584. Network-reachable code execution inside an endpoint security product is operationally severe — successful exploitation lands attacker code in the same privileged context as Defender. Treat the Engine version verification step as covering both CVEs.
