CVE-2026-41091

HIGH(7.8)KEV

Microsoft Defender Link Following Vulnerability

Description

CVE-2026-41091 is a high-severity link following (improper link resolution before file access) vulnerability in Microsoft Defender. By exploiting how Defender resolves file links before accessing files, an authorized local attacker can elevate their privileges on the system. Because Defender's Malware Protection Engine runs with high privileges, redirecting its file operations through attacker-controlled links can grant full SYSTEM-level control from an ordinary user account. With a CVSS score of 7.8, an EPSS score in the 90th percentile, and a CISA KEV listing, CVE-2026-41091 is being exploited and should be remediated promptly on affected systems.

KEV Information

Vendor
Microsoft
Product
Defender
Date Added
May 20, 2026
Due Date
June 3, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftmalware protection engine>= 1.1.26030.3008, < 1.1.26040.8

References

Weakness Type

CWE-59: Improper Link Resolution Before File Access ('Link Following')

In Microsoft Defender, the engine accesses a file by following a link without adequately verifying its target, so an attacker who controls the link (for example a symbolic link or junction) can redirect a privileged file operation to a location of their choosing. This lets a low-privileged user trick the high-privilege Defender process into reading or writing files it should not, resulting in privilege escalation.

Learn more: CWE-59 — Improper Link Resolution Before File Access ('Link Following')

Impact Analysis

CVE-2026-41091 carries a CVSS 3.1 score of 7.8 (HIGH). The attack vector is local with low attack complexity and requires only low privileges and no user interaction, and on success it fully compromises the confidentiality, integrity, and availability of the host. The practical consequence is local privilege escalation: an attacker who already has a foothold as a standard user can abuse Defender's privileged file handling to gain SYSTEM-level control, a common and valuable step in post-compromise activity. The EPSS score of 5.9% sits in the 90.7th percentile, and the CISA KEV listing confirms exploitation in the wild, so this is a priority patch even though it requires local access.

Exploit Maturity

CVE-2026-41091 is on the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation, and its EPSS score of 5.9% (90.7th percentile) reflects elevated exploitation likelihood relative to most CVEs. No exploit-tagged public proof-of-concept appears in the NVD references — the primary source is the Microsoft MSRC advisory — but link-following privilege-escalation techniques against security products are well understood and frequently chained into attack toolkits. Because Defender updates its engine automatically, most systems will receive the fix through normal update channels, but defenders should verify the engine version and treat any local-privilege-escalation indicators seriously.

Remediation

  1. Apply mitigations per vendor instructions as mandated by the CISA KEV deadline of 2026-06-03: ensure the Microsoft Malware Protection Engine is updated to version 1.1.26040.8 or later — affected versions span 1.1.26030.3008 up to (but not including) 1.1.26040.8.
  2. Confirm that automatic engine and definition updates are enabled for Microsoft Defender, since the fix is delivered through the engine update channel; verify the deployed engine version across the estate.
  3. Apply least-privilege principles so standard users cannot create symbolic links or junctions in locations that privileged processes access, reducing the opportunity to exploit link-following flaws.
  4. Monitor for local privilege-escalation indicators such as unexpected SYSTEM-level process creation, suspicious symlink/junction creation, and anomalous file operations by the Defender engine.
  5. As long-term hardening against link-following vulnerabilities, ensure privileged services canonicalize and validate file paths and resolve links safely before access, and keep endpoint security components on their latest engine builds.

Technical Details

CVE-2026-41091 is an improper link resolution before file access vulnerability (CWE-59) in Microsoft Defender's Malware Protection Engine. When the engine accesses a file via a link without securely validating where that link points, a local attacker who can control the link target can redirect a privileged file operation, causing Defender to act on a file the attacker chooses — a classic link-following primitive for privilege escalation. The CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects a local, low-complexity attack requiring only low privileges and no user interaction, with full impact to confidentiality, integrity, and availability. Affected builds run from Malware Protection Engine 1.1.26030.3008 up to but not including 1.1.26040.8, which contains the fix.

Frequently Asked Questions

Is CVE-2026-41091 being actively exploited?

Yes. CVE-2026-41091 is listed on the CISA Known Exploited Vulnerabilities catalog, and its EPSS score of 5.9% places it in the 90.7th percentile for exploitation likelihood, indicating it is being exploited in the wild as a local privilege-escalation vector.

What products are affected by CVE-2026-41091?

The vulnerability affects the Microsoft Malware Protection Engine (used by Microsoft Defender) in versions from 1.1.26030.3008 up to but not including 1.1.26040.8.

How do I fix CVE-2026-41091?

Ensure the Microsoft Malware Protection Engine is updated to version 1.1.26040.8 or later. Because the engine updates automatically, verify that automatic updates are enabled and confirm the deployed engine version across your systems.

How severe is CVE-2026-41091?

CVE-2026-41091 is rated HIGH with a CVSS 3.1 score of 7.8. It allows an authorized local attacker to elevate privileges by abusing Defender's link handling, potentially gaining SYSTEM-level control from a standard user account.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score9.64%
EPSS Percentile95.1%

Dates

PublishedMay 20, 2026
Last ModifiedJuly 24, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.