LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-41091: Microsoft Defender Link Following Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-41091 to its Known Exploited Vulnerabilities catalog on May 20, 2026, with a federal patch deadline of Jun 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

Microsoft Defender contains a link following vulnerability that permits an authorized local attacker to elevate privileges. The flaw affects the way the product resolves file paths, which can be abused on systems where Defender is installed and running.

How it works

The weakness is categorized as CWE-59, improper link resolution before file access. An attacker with existing local access can supply a crafted link that the product follows to a privileged location. This allows the attacker to perform actions at a higher privilege level than originally granted. Specific mechanics of exploitation, affected code paths, and required preconditions are not detailed in the available summary and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Defender runs on Windows endpoints as part of the operating system or as a standalone security agent. Inventory all systems that have Defender enabled, including workstations, servers, and any virtualized or cloud-hosted instances. Examine installed versions and configuration settings, particularly those that control file scanning, link handling, or integration with the file system. Compare results directly against the vendor advisory, as no specific version list is provided here. Telemetry to review includes process creation events involving Defender components, unexpected file or directory access attempts, and any local privilege changes recorded in security logs.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary remediation. After patching, review Defender configuration for any settings that influence path resolution or symbolic link handling and adjust them according to vendor guidance. Maintain least-privilege access for accounts that interact with Defender and ensure endpoint logging captures relevant file-system and process events for ongoing verification.

If you can't patch immediately

Follow the mitigations specified in the vendor instructions. Where Defender is used in cloud services, apply applicable guidance from CISA BOD 22-01. If suitable mitigations cannot be implemented, discontinue use of the affected product until an update can be deployed. Additional compensating steps for this class of issue include restricting local user permissions on endpoints and monitoring for anomalous link or path operations until the patch is applied.

If your data may have been exposed

Privilege-escalation vulnerabilities can be used to expand access during an intrusion. Organizations should assume that successful local exploitation may have enabled further actions on affected systems. Run a free exposure scan of organizational email addresses against known breach data to identify any prior incidents that may be related.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Defender
WeaknessCWE-59
Added to CISA KEVMay 20, 2026
Federal patch deadlineJun 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities