CVE-2026-45584: Microsoft Malware Protection Engine
High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
Affected products
- Microsoft Malware Protection Engine: from 1.1.26030.3008, before 1.1.26040.8 (fixed in 1.1.26040.8)
Published 2026-05-20. Last modified 2026-07-23.