CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
How it works
The weakness is categorized as CWE-1220, insufficient granularity of access control. In this class of flaw, permissions assigned to an authorized user or process are broader than required for the intended function. An attacker who already possesses limited local access can therefore reach actions or data that should be restricted, resulting in privilege escalation on the affected system.
Am I affected? How to find it in your systems
Microsoft Defender runs on Windows endpoints and servers as part of the operating-system security stack. Inventory instances through standard software listings, endpoint-management consoles, or configuration-management databases. Confirm the precise versions and configurations in use against the vendor advisory, as the vulnerability description does not enumerate specific builds.
- Review local security logs and Microsoft Defender operational logs for unexpected privilege changes or policy modifications initiated by standard user accounts.
- Correlate any anomalous local process behavior with Defender components, because exploitation occurs after initial local access.
How to remediate
Apply mitigations per the vendor instructions provided in the official advisory. After the update is deployed, review Defender policy settings to ensure the principle of least privilege is enforced for all local accounts and service principals that interact with the product.
- Revalidate access-control lists and feature permissions following the update.
- Confirm that cloud-service components, if present, align with applicable BOD 22-01 guidance.
If you can't patch immediately
Until the vendor update can be applied, follow the CISA required actions: implement mitigations according to vendor instructions, adhere to BOD 22-01 guidance for any cloud services, or discontinue use of the product if mitigations are unavailable. Segment endpoints so that standard user accounts cannot reach Defender management interfaces, and increase monitoring for local privilege-escalation indicators.
If your data may have been exposed
Actively exploited vulnerabilities of this type have led to breaches. Organizations can run a free exposure scan of their email domains to check for presence in known breach data.
AICompiled with AI assistance from public sources and published under our editorial standards.