CVE-2026-33825 is a privilege escalation vulnerability affecting Microsoft Defender that stems from insufficient access control granularity, allowing an authorized local attacker to elevate their privileges on a compromised system. The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector, low complexity, and low privilege requirements, resulting in high impact across confidentiality, integrity, and availability. The vulnerability is actively being exploited in the wild and appears on CISA's Known Exploited Vulnerabilities list, indicating mature threat actor activity. With an EPSS score of 0.138 and a FAUCET Risk Score of 87.0/100, this represents a significant threat that is being preferentially targeted by adversaries. Organizations running Microsoft Defender should prioritize patching immediately given the active exploitation status and the ease with which authenticated attackers can escalate to system-level access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.18.26030.3011CPE matchmatch criteria | cpe:2.3:a:microsoft:defender_antimalware_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.