CVE-2026-45498

MEDIUM(4.0)KEVLikely Exploited

Microsoft Defender Denial of Service Vulnerability

Description

CVE-2026-45498 is a medium-severity denial of service vulnerability in Microsoft Defender, categorized as uncontrolled resource consumption. A local attacker can trigger the flaw to degrade or interrupt the availability of the Defender antimalware platform, undermining the very protection it is meant to provide. While the impact is limited to availability — confidentiality and integrity are not affected — disabling endpoint protection can create a window for other attacks to proceed undetected. With a CVSS score of 4.0, an EPSS score in the 88th percentile, and a CISA KEV listing, CVE-2026-45498 is being exploited and the affected Defender component should be updated promptly.

KEV Information

Vendor
Microsoft
Product
Defender
Date Added
May 20, 2026
Due Date
June 3, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.5
Impact Score
1.4

CWEs

Affected Products

VendorProductVersion
microsoftdefender antimalware platform< 4.18.26040.7

Multiple CVSS Assessments

Source: [email protected](Secondary)
4.0
MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Source: [email protected](Primary)
7.5
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

Weakness Type

CWE-400: Uncontrolled Resource Consumption

In the Microsoft Defender antimalware platform, uncontrolled resource consumption allows a local attacker to drive the engine to exhaust available resources, resulting in a denial of service. Because the platform does not adequately bound the resources a given operation can consume, the condition degrades or halts Defender's protective function.

Learn more: CWE-400 — Uncontrolled Resource Consumption

Impact Analysis

CVE-2026-45498 carries a CVSS 3.1 score of 4.0 (MEDIUM). The attack vector is local with low attack complexity, requires no privileges and no user interaction, and impacts only availability — confidentiality and integrity are not affected, and the scope is unchanged. The practical effect is a denial of service against the Defender antimalware platform: an attacker able to run code locally can disrupt or disable endpoint protection on the host. Although the direct impact is limited, the loss of Defender's protection can serve as an enabler for other malicious activity to run undetected. The EPSS score of 4.1% sits in the 88.7th percentile, and the CISA KEV listing confirms the flaw is exploited in the wild, warranting prompt remediation despite the moderate severity rating.

Exploit Maturity

CVE-2026-45498 is on the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation, and its EPSS score of 4.1% (88.7th percentile) reflects elevated exploitation likelihood relative to most vulnerabilities. No exploit-tagged public proof-of-concept appears in the NVD references — the sole vendor source is the Microsoft MSRC advisory, and the NVD description itself is minimal — but because the flaw can disable endpoint protection, defenders should ensure the Defender antimalware platform is current. As the platform updates automatically, most systems will receive the fix through normal channels; verify the deployed version and monitor for unexpected Defender service interruptions.

Remediation

  1. Apply mitigations per vendor instructions as mandated by the CISA KEV deadline of 2026-06-03: ensure the Microsoft Defender antimalware platform is updated to version 4.18.26040.7 or later, which addresses the issue.
  2. Confirm that automatic platform and definition updates are enabled for Microsoft Defender, since the fix is delivered through the platform update channel; verify the deployed version across the estate.
  3. Monitor Defender service health and availability so that a denial-of-service condition — and any malicious activity it may be intended to mask — is detected quickly.
  4. Maintain defense in depth so that a temporary loss of Defender protection does not leave endpoints unmonitored; complementary EDR/telemetry and network controls reduce the blast radius of an availability impact.
  5. As long-term hardening against uncontrolled resource consumption, keep endpoint security components on their latest builds and ensure resource limits and watchdog/restart mechanisms are in place for critical protective services.

Technical Details

CVE-2026-45498 is an uncontrolled resource consumption vulnerability (CWE-400) in the Microsoft Defender antimalware platform that results in a denial of service. The NVD provides only a brief description, but the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) characterizes the flaw precisely: the attack is local and low-complexity, requires no privileges and no user interaction, leaves the scope unchanged, and affects only availability (with no confidentiality or integrity impact). In practice, a local actor can cause the Defender platform to consume resources to the point of disrupting its operation. The fix is included in Defender antimalware platform version 4.18.26040.7 and later.

Frequently Asked Questions

Is CVE-2026-45498 being actively exploited?

Yes. CVE-2026-45498 is listed on the CISA Known Exploited Vulnerabilities catalog, and its EPSS score of 4.1% places it in the 88.7th percentile, indicating it is being exploited in the wild as a denial-of-service vector against Microsoft Defender.

What products are affected by CVE-2026-45498?

The vulnerability affects the Microsoft Defender antimalware platform in versions before 4.18.26040.7.

How do I fix CVE-2026-45498?

Ensure the Microsoft Defender antimalware platform is updated to version 4.18.26040.7 or later. Because the platform updates automatically, verify that automatic updates are enabled and confirm the deployed version across your systems.

How severe is CVE-2026-45498?

CVE-2026-45498 is rated MEDIUM with a CVSS 3.1 score of 4.0. The impact is limited to availability — it allows a local attacker to cause a denial of service against Defender — but disabling endpoint protection can facilitate other attacks, so it warrants prompt patching.

CVSS Score

4.0
MEDIUM(4.0)

EPSS Score

EPSS Score63.08%
EPSS Percentile99.1%

Dates

PublishedMay 20, 2026
Last ModifiedJuly 23, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.