LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 22, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 6, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-33825 to its Known Exploited Vulnerabilities catalog on Apr 22, 2026, with a federal patch deadline of May 6, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. The issue is tracked as CVE-2026-33825 and has been observed in ransomware campaigns. Organizations running Microsoft Defender should treat local privilege-escalation paths in security tooling as high-priority items because they can undermine endpoint protections.

How it works

The weakness is categorized as CWE-1220, insufficient granularity of access control. In this class of flaw, permissions assigned to an authorized user or process are broader than required for the intended function. An attacker who already possesses limited local access can therefore reach actions or data that should be restricted, resulting in privilege escalation on the affected system.

Am I affected? How to find it in your systems

Microsoft Defender runs on Windows endpoints and servers as part of the operating-system security stack. Inventory instances through standard software listings, endpoint-management consoles, or configuration-management databases. Confirm the precise versions and configurations in use against the vendor advisory, as the vulnerability description does not enumerate specific builds.

How to remediate

Apply mitigations per the vendor instructions provided in the official advisory. After the update is deployed, review Defender policy settings to ensure the principle of least privilege is enforced for all local accounts and service principals that interact with the product.

If you can't patch immediately

Until the vendor update can be applied, follow the CISA required actions: implement mitigations according to vendor instructions, adhere to BOD 22-01 guidance for any cloud services, or discontinue use of the product if mitigations are unavailable. Segment endpoints so that standard user accounts cannot reach Defender management interfaces, and increase monitoring for local privilege-escalation indicators.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to breaches. Organizations can run a free exposure scan of their email domains to check for presence in known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Defender
WeaknessCWE-1220
Added to CISA KEVApr 22, 2026
Federal patch deadlineMay 6, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities