Impact
Microsoft reports an elevation of privilege flaw in its Malware Protection Engine, a core component of Microsoft Defender, that has been publicly referred to and could allow a malicious actor to gain higher privileges within the system. The description does not specify suggesting local presence or an existing foothold.
Affected Systems
The flaw affects the Microsoft Malware Protection Engine, which is the primary part of Microsoft Defender on Windows platforms. No particular version numbers are listed, implying that all current releases of the engine may be impacted until a vendor patch is issued.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is rated as high severity, and the EPSS score of 3% indicates a moderate probability of exploitation. The flaw is not listed in the CISA KEV catalog. Because the reported information does not provide a clear attack vector, the likely scenario involves local or pre‑existing system access; remote exploitation is not confirmed.
OpenCVE Enrichment