CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2026-04-22. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Affected products

  • Microsoft Defender Antimalware Platform: before 4.18.26030.3011 (fixed in 4.18.26030.3011)

Published 2026-04-14. Last modified 2026-07-24.