CVE-2026-41091: Microsoft Defender Symlink Following — Low-Privilege to SYSTEM via Malware Protection Engine
Microsoft — Defender (Microsoft Malware Protection Engine)
A link-following vulnerability in the Microsoft Malware Protection Engine allows a low-privilege local attacker to gain SYSTEM privileges by manipulating Defender into operating on attacker-controlled targets. Actively exploited in the wild.