Description
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A time‑of‑check time‑of‑use (TOCTOU) race condition exists in Microsoft Defender for Endpoint for Mac that permits an attacker with local authorization to elevate privileges. The flaw arises when the software checks a file or resource state and the state changes before the operation completes, enabling the attacker to manipulate the operation and gain elevated rights. The weakness is classified as CWE‑367, which reflects improper handling of resource state during concurrent operations.

Affected Systems

Microsoft Defender for Endpoint for Mac is the affected product. No specific version range is provided in the public data, indicating all installed instances may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 7.0 indicates a medium severity, and the EPSS score of less than 1% suggests that, while exploitation is possible, it is currently unlikely to occur at scale. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker with user-level access on the machine would need to trigger the race condition, which may maliciously timed actions. Due to the medium severity score, organizations should treat this as a priority risk when Microsoft releases a fix.

Generated by OpenCVE AI on July 31, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Defender for Endpoint for Mac update released by Microsoft through the Security Response Center.
  • Restrict privileged operations for local users and enforce least‑privilege principles to reduce the window for race condition exploitation.
  • Enable and review security event logging to detect unusual privilege escalation attempts on the affected system.

Generated by OpenCVE AI on July 31, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Title Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft defender For Endpoint
Weaknesses CWE-367
CPEs cpe:2.3:a:microsoft:defender_for_endpoint:*:*:*:*:*:macos:*:*
Vendors & Products Microsoft
Microsoft defender For Endpoint
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Defender For Endpoint
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:29.810Z

Reserved: 2026-06-05T14:33:50.831Z

Link: CVE-2026-50658

cve-icon Vulnrichment

Updated: 2026-07-14T19:18:16.508Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:30:04Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition