Description
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
Published: 2026-08-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Microsoft Defender for Endpoint for Mac allows an authorized attacker to expose sensitive local information. The vulnerability is classified as an information disclosure weakness (CWE-200) and can compromise confidentiality if an attacker gains access to the local environment. Developers and administrators should recognize that the exposure does not enable remote code execution or elevation, but it permits retrieval of data that should remain confidential.

Affected Systems

The affected product is Microsoft Defender for Endpoint for Mac. No specific affected releases or version numbers are provided in the advisory, so any deployment that has not been updated to the latest release may be vulnerable.

Risk and Exploitability

The CVSS score of 5.5 reflects a moderate impact, while the EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local – an attacker with authorized user privileges on the device could exploit the flaw. Although exploitation conditions are minimal, the affected information may remain within the local scope.

Generated by OpenCVE AI on August 12, 2026 at 15:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Microsoft Defender for Endpoint for Mac update from the Microsoft Security Response Center.
  • If an update is not yet available, restrict privileged local accounts and disable any unnecessary network services that could expose data from the device.
  • Monitor Defender logs for any anomalous local data exposure and adjust configuration settings to enforce the principle of least privilege.

Generated by OpenCVE AI on August 12, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
Title Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft defender For Endpoint
Weaknesses CWE-200
CPEs cpe:2.3:a:microsoft:defender_for_endpoint:*:*:*:*:*:macos:*:*
Vendors & Products Microsoft
Microsoft defender For Endpoint
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Defender For Endpoint
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:31.434Z

Reserved: 2026-06-11T20:33:37.836Z

Link: CVE-2026-54123

cve-icon Vulnrichment

Updated: 2026-08-12T13:24:57.285Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:03.647

Modified: 2026-08-17T12:06:36.043

Link: CVE-2026-54123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T15:45:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor