Impact
The CVE identifies a denial of service vulnerability in the Microsoft Defender Antimalware Platform. This flaw is classified as CWE-400, indicating uncontrolled resource consumption. The description is limited to this statement, without detailing how the vulnerability is triggered. It is inferred that an attacker could exploit the platform to disrupt its operation, causing a loss of protection, but the exact exploitation method is not disclosed.
Affected Systems
The listed vendor/product is Microsoft Defender Antimalware Platform. No specific version details are provided in the CNA data; therefore any installation of this platform on supported Windows configurations might be at risk. Administrators should check which version of Defender is installed and ensure it is current.
Risk and Exploitability
The CVSS score is 4, indicating moderate severity. The EPSS score of 1% indicates a very low likelihood of exploitation, roughly 1% probability. The vulnerability is listed in the CISA KEV catalog, signalling that it is actively exploited in the wild, though the exact attack surface is not disclosed. Because the vector is not specified, it is inferred that local or privileged access may be necessary, but this cannot be confirmed. Given the moderate severity and low exploitation probability, the overall risk is lower but patching is still recommended.
OpenCVE Enrichment